Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill’s stated purpose is narrowly scoped to GB/T 9704-2012 公文 formatting, but the described implementation behavior includes unrelated hardcoded report conversion, generic checklist output, and brittle content-specific truncation logic. In an agent setting, this can cause silent misprocessing of user documents, loss of content, or fabrication of structure while presenting the result as standards-compliant, which is a security-relevant integrity issue.
