Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 83% confidence
- Finding
- The skill claims semantic security scanning but the described behavior suggests broader scanning, caching, reporting, and prompt construction for a second-layer LLM analysis that is not actually performed locally. This mismatch can mislead users into overtrusting results, especially for security decisions, and can cause unsafe handling of adversarial skill content if operators assume deeper analysis occurred when it did not.
