Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 80% confidence
- Finding
- The skill markets itself as a keepalive mechanism, but the documented behavior extends into persistence setup, service installation/bootstrap, credential storage, and outbound notification traffic. This broader operational scope increases risk because users may approve it expecting passive monitoring while it actually establishes persistent background services and stores secrets locally.
