Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The skill metadata says it generates copy-paste bash scripts, but the content also instructs users to run autonomous agent CLIs, modify project files, execute tests, and invoke external notification tooling. That mismatch is security-relevant because users may grant trust or permissions based on the declared purpose while the actual workflow performs materially more powerful actions.
