Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The skill relies on browser automation, subprocess execution, temporary file creation, and parsing of remote content, which expands the attack surface substantially beyond the stated purpose. When paired with shell and network access, this can expose the agent to command misuse, untrusted content handling, or unsafe local execution paths if the helper scripts are not tightly constrained.
