Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 88% confidence
- Finding
- The skill is presented as scanning repository agent configuration files, but the finding indicates the underlying implementation also scans broader code and may perform live network access to external registries. That mismatch is dangerous because users may authorize the skill under a narrower trust model than its actual behavior, enabling unintended data exposure or outbound connections during a supposedly local config review.
