Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill metadata says it only produces an intermediate artifact for user review, but the body also instructs the agent to invoke data-generator and describes producing full JSONL training records. That mismatch is dangerous because downstream systems or users may grant it broader trust than intended, leading to unreviewed generation, unexpected data handling, and possible persistence of sensitive context.
