Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
The skill contains standalone read/verification behavior not reflected in the concise declared purpose. While not inherently malicious, undocumented verification endpoints and read-side API calls still matter in a security review because they can leak identifiers, confirm resource existence, or create unanticipated audit traffic.
- Content
