Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The skill description narrows the purpose to a source-saving knowledge base and says it should not be used for bookmark management or fetching without saving, but the command surface adds broader queue management, bulk import, synthesis, and stats features. This mismatch can cause the agent or user to invoke behaviors they did not meaningfully consent to, expanding persistence and processing beyond the stated scope.
