Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill claims to operate specifically on SNU's Canvas LMS and to validate the configured URL first, but the documented bridge accepts an arbitrary lx-agent subcommand and does not itself enforce any SNU- or Canvas-specific restriction. This mismatch is dangerous because an agent may trust the description and invoke broader functionality than intended, including commands or targets outside the declared scope.
