Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill is presented as a crawler for public Xiaohongshu content, but the documented behavior goes beyond simple scraping by collecting authenticated session cookies, persisting scraped data and screenshots locally, and describing anti-detection/anti-crawling evasion techniques such as webdriver hiding, simulated human behavior, UA rotation, and proxy rotation. This mismatch is dangerous because it conceals privacy-sensitive credential handling and platform-evasion capabilities that could be used for unauthorized data collection, account misuse, or terms-of-service circumvention.
