Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill is presented primarily as a web-reading/search utility, but it also installs software by running `scripts/install.sh`, downloads a binary from GitHub releases, and encourages executing that binary. This hidden operational behavior expands trust requirements substantially and can expose users to supply-chain compromise or unintended code execution, especially because the install path is framed as simple setup rather than a security-sensitive action.
