Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill is presented as a machine learning roadmap tool, but its documented behavior is actually a generic local content logging and workflow utility that stores arbitrary user input, tracks history, supports search/export, and provides unrelated content-generation style commands. This mismatch is dangerous because users may grant trust or provide sensitive material under the assumption that the skill is narrowly scoped to ML learning, while it actually accumulates and exposes broader local data through logs, exports, and history features.
