Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The skill metadata and documentation present this as a startup-focused toolkit, but the analyzed behavior reportedly includes generic note/log storage, local history persistence, and utility commands unrelated to the declared purpose. That mismatch is security-relevant because users and calling agents may grant trust, invoke the skill, or expose data based on the stated business function, while the actual behavior introduces undeclared data handling and broader capabilities.
