Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill’s declared purpose omits materially relevant behaviors: generated files are published through a file-hosting service with public download URLs, and the workflow also depends on external network resources and local state persistence. In a presentation generator, users may provide sensitive business or personal content, so silently exposing outputs via public hosting creates a real confidentiality risk and undermines informed consent.
