Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The documented purpose is restaurant info lookup and queueing, but the analyzed behavior reportedly extends to account authentication, token acquisition, shell-based global package installation, remote downloads from Gitee, and runtime self-updating of the skill. That combination materially expands the trust boundary and creates supply-chain and remote code execution risk far beyond what a user would reasonably expect from a restaurant helper skill.
