Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The skill markets itself as providing live multi-calendar planning across Google, Outlook, Apple Calendar, and CalDAV, but the analyzed content appears to only describe local analysis scripts and playbooks rather than actual adapter enforcement or connectivity. This mismatch can mislead users into granting trust, installing dependencies, or exposing calendar exports under false assumptions about what the skill can really do and what controls are actually implemented.
