Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill markets itself as a content/trend automation assistant, but the documented behavior expands into persistent memory, profiling, workflow retention, and references to external scripts and local storage behaviors that are not clearly disclosed in the top-level description. This mismatch is dangerous because users may consent to a lightweight reporting skill while unknowingly enabling broader data retention or execution-related capabilities, undermining informed consent and increasing the attack surface.
