Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill is presented as a simple educational idiom feature, but the documentation also advertises push-management capabilities that affect user state, scheduling, and external delivery channels. That mismatch matters because users and reviewers may not expect background notifications, per-user config changes, or outbound messaging integrations from the stated purpose, increasing the chance of unauthorized or insufficiently consented behavior.
