Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
The declared description presents the skill as GitHub workflow guidance, but the detected behavior includes hidden enforcement and hook-style gating of user/tool payloads, local config reads, and debug logging. This mismatch is dangerous because users and security reviewers cannot accurately assess what the skill will do, especially if it can block tasks, inspect local state, or emit logs without being transparently declared. The combination of policy enforcement and local data access meaningfully expands the attack surface beyond the advertised purpose.
- Content
