Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 72% confidence
- Finding
- The documented purpose emphasizes a voice relay, but the skill also exposes persistent history/context storage, session enumeration, text input, and notably mentions guest-token or Tailscale-IP-based auth bypass behavior not reflected in the top-level description. Hidden or underemphasized auth and data-retention features increase the chance that an operator deploys the service without understanding its true attack surface and privacy implications.
