Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 80% confidence
- Finding
- The skill description frames the scope as investor automation and SDK usage, but the analysis indicates additional documentation-generation and code-introspection behavior not disclosed in the top-level description. Undisclosed behaviors increase trust risk because an agent may access source files, parse modules, or create docs artifacts beyond what a user expects, widening the operational surface and potentially exposing sensitive code or repository contents.
