Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
- The skill is presented as a local self-evolution engine, but the documented behavior materially expands its scope to remote hub communication, task execution, publishing, daemon/lifecycle control, and downloading/writing remote skills. That mismatch undermines informed consent and review, because an operator may grant powerful network and shell capabilities without understanding the full operational surface and supply-chain risk.
