Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill is presented as a passive logging aid, but the instructions expand into hook-based automatic execution, tool-output scanning, virtual prompt injection, and even scaffolding new skills. That mismatch is dangerous because users or agents may grant it broader trust than warranted, enabling persistent automation and behavior changes under a benign-sounding description.
