Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The manifest and top-level description position the skill as comment-only, but the body documents broader behaviors: keyword search, note detail retrieval including正文, creator profile/post monitoring, URL construction, and local logging. This mismatch is dangerous because callers, policy engines, or users may grant trust and supply data under a narrower expectation, while the skill can collect and process a materially larger dataset than advertised, increasing privacy, compliance, and data-exfiltration risk.
