Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
Writing schema snapshot files and actively probing endpoint schemas contradicts the claimed read-only design. In this context, that is more dangerous because the skill is presented as a safe, bundled-data reader; unexpected writes can tamper with trusted local artifacts, and active schema probing can introduce uncontrolled network interactions and persistence of untrusted remote data.
- Content
