Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill is presented as a customer-service calling tool, but it also provisions a phone number, answers inbound calls, stores a long-lived token locally, polls account status, and updates answering prompts. That broader behavior materially changes the privacy and security posture because users may authorize it for outbound calling without realizing it can autonomously receive calls and collect transcripts/recordings.
