Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The skill is presented as a narrowly scoped fault-diagnosis workflow, but the documented interface exposes a much broader capability surface through a generic LakeWatch API client, proxy access to manager APIs, and references to credential/token handling and auxiliary CLI functions. That mismatch is dangerous because downstream agents or reviewers may trust the stated read-only diagnostic scope while the actual toolchain can access additional endpoints and sensitive operational data, increasing the chance of overbroad API use or privilege abuse if the client/config is manipulated.
