Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill description materially understates behavior by framing the skill as a quality-enforcement loop while the body also performs session injection, outbound messaging, interactive control flow, and consumes user replies to drive execution. In a high-privilege skill where workers inherit exec, OAuth-backed tools, and all installed skills, this mismatch can mislead users into authorizing a much broader and riskier orchestration capability than expected.
