Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 86% confidence
- Finding
- The published description presents the skill as a narrow 'pick hot/recent posts' capability, but the body instructs the agent to also fetch note details, comments, and creator post histories, with broader sort and time-range options. This mismatch can cause users or orchestrators to invoke the skill under weaker consent assumptions than the actual data collection scope, increasing the risk of over-collection and unintended third-party data disclosure to the external API.
