Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
If the implementation does not actually perform the promised transcription/link processing and instead accesses local filesystem/package metadata, the skill is misrepresenting what data it touches. That is dangerous because users may provide sensitive local paths or expect cloud transcription while the skill performs unrelated local inspection, creating a trust and privacy boundary violation.
- Content
