Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
- The skill description claims no file I/O, subprocess execution, or environment access, but the documented behavior involves reading compiler-related environment state, checking files, linking object files, and executing a produced native binary. This mismatch is dangerous because reviewers may trust the benign description while the actual workflow introduces native-code execution and supply-chain risk from bundled object files and PATH/compiler selection.
