Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 87% confidence
- Finding
- The skill description emphasizes memory and mission-control features, but the referenced setup behavior includes OAuth registration, local callback handling, token exchange, and writing credentials to a local secrets file. Those are sensitive authentication operations with significant security implications, and omitting them from the primary description can prevent informed consent and lead users to enable the skill without understanding credential-handling risk.
