Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 86% confidence
- Finding
- The skill is presented as a debugging workflow, but it explicitly instructs use of a diagnostics script that captures environment state and mentions collecting repository, configuration, and environment details. That expands behavior beyond pure debugging guidance into potentially sensitive data collection, creating a risk of over-collection and leakage of secrets, internal URLs, filesystem paths, or repository metadata if the report is shared, logged, or sent to other tools.
