Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill’s declared purpose is a simple quote-card generator, but the documentation introduces materially different capabilities: scheduled push delivery, multi-channel outbound messaging, and user-specific state/config handling. This mismatch is dangerous because reviewers and users may grant the skill permissions or trust assumptions appropriate for content generation, while the actual documented behavior expands into notification automation and external delivery, increasing the chance of undisclosed data handling or misuse.
