Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The manifest frames the skill as a logging utility, but the body also describes prompt-injection hooks, output scanning, cross-file promotion into persistent agent context, and skill generation. That mismatch can mislead users and reviewers about the actual authority and side effects of the skill, increasing the chance that broader persistence and behavior-shaping features are enabled without informed consent.
