Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- This appears to be a real security issue because the documented purpose of the skill does not match the described runtime behavior: it reportedly logs into a fixed host with hardcoded credentials, captures screenshots, and automates a generic internal-looking web UI rather than clearly interfacing with Ozon or a documented Crossrui API. In an agent skill, that mismatch is dangerous because it can conceal credential misuse, unauthorized access to an internal service, data leakage via screenshots, and unintended actions on a third-party or internal system.
