Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The skill claims a local Excel translation workflow but discloses that workbook cell contents are sent to an external OpenAI-compatible API. This can expose sensitive spreadsheet data to a third party without clear user consent, and the claims about preserving charts/behavior are overstated, which may mislead users about data handling and output integrity.
