Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The skill metadata presents Buddy as a simple pet interaction tool, but the documented behavior includes hidden or under-disclosed capabilities: context-injection prompt generation, persistent local state, and privileged/demo-style pet generation. That mismatch matters because users and orchestrators may grant trust or invoke the skill under false assumptions, enabling unintended persistence and prompt-surface manipulation that can affect later model behavior.
