Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill’s stated purpose is narrowly scoped to domain controller lifecycle management, but the documented behavior explicitly includes a reusable QEMU guest agent execution path that can run arbitrary PowerShell inside Windows guests and pass secrets via stdin. That broader capability materially expands the trust boundary: if invoked with attacker-influenced inputs or against the wrong VM, it becomes a privileged remote-execution mechanism on domain infrastructure rather than just a constrained rebuild workflow.
