Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill claims to scan repository agent configuration files, but the referenced scanner behavior reportedly extends into broader code auditing, secret detection, package analysis, and network-based verification. That scope expansion materially changes the trust boundary: a user invoking a narrowly scoped config scanner may unknowingly permit broader repository inspection and outbound dependency lookups.
