Back to skill

Security audit

Kaipai

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly aligned with image and video processing, but it uses sensitive credentials, remote configuration, arbitrary URL fetching, and worker delegation with insufficient guardrails.

Install only in an isolated, trusted OpenClaw environment. Use scoped Kaipai and messaging credentials, avoid giving it untrusted media URLs unless URL filtering is added, and review the remote-configuration and spawned-worker paths before production use. Expect paid quota consumption and local task history containing media links.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
sdk/core/client.py:166
Finding

Arbitrary URL Fetch Enables SSRF and Exfiltration Through Remote Media Upload

Content
View full analysis

Vulnerability Details

File Location: sdk/core/client.py:166-186, sdk/core/client.py:207-226; duplicate URL-fetch behavior in scripts/kaipai_ai.py:269-290
Vulnerability Type: Server-Side Request Forgery followed by remote data upload
Risk Level: High

Vulnerable Code

python
def _download_to_temp(self, url: str) -> Tuple[str, int]:
    """Download URL to temp file. Returns (path, size)."""
    max_b = url_download_max_bytes()
    conn_t = url_download_connect_timeout()
    read_t = url_download_read_timeout()

    resp = requests.get(
        url,
        stream=True,
        timeout=(conn_t, read_t),
        headers={"User-Agent": USER_AGENT},
    )
    resp.raise_for_status()

    fd, path = tempfile.mkstemp(prefix="kaipai_in_", suffix=".bin")
    total = 0
    try:
        with os.fdopen(fd, "wb") as f:
            for chunk in resp.iter_content(chunk_size=65536):
                if chunk:
                    total += len(chunk)
                    if total > max_b:
                        raise RuntimeError(f"File too large (max {max_b} bytes)")
                    f.write(chunk)
    except Exception:
        os.unlink(path)
        raise
    return path, total
python
if source.startswith(("http://", "https://")):
    _progress_log(f"Downloading from URL: {source[:64]}...")
    tmp_path, size = self._download_to_temp(source)
    try:
        _progress_log(f"Downloaded {size} bytes, uploading to OSS...")
        url_data = self.api.upload_file(tmp_path)
    finally:
        os.unlink(tmp_path)

Technical Analysis

The client accepts any URL beginning with http:// or https://. It does not validate the resolved IP address, reject loopback or private address ranges, block cloud metadata services, or restrict the destination to approved media providers.

The default behavior of requests.get() also follows redirects. Cons ...[truncated 1647 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse URLs using urllib.parse.urlsplit() and permit only HTTPS unless HTTP is explicitly necessary.
  2. Resolve all destination hostnames before connecting and reject loopback, private, link-local, multicast, unspecified, and reserved IP ranges for both IPv4 and IPv6.
  3. Explicitly block cloud metadata addresses and hostnames, including link-local metadata endpoints.
  4. Disable redirects or validate the destination hostname and resolved IP after every redirect.
  5. Defend against DNS rebinding by connecting only to the validated address and ensuring the HTTP host and TLS certificate match the approved hostname.
  6. Prefer an allowlist of trusted media/CDN domains where practical.
  7. Validate the response MIME type and file signature before upload.
  8. Apply one centralized URL-validation implementation to run-task, resolve-input, cover-image downloads, and all duplicate download paths.
  9. Avoid uploading fetched content until it has passed media validation.

T09 · Insecure Skill Coding Practices

Error
Location
sdk/cli/commands.py:413
Finding

Untrusted Delivery Values Are Embedded in Spawned-Agent Shell Instructions

Content
View full analysis

Vulnerability Details

File Location: sdk/cli/commands.py:413-448
Vulnerability Type: Command injection and spawned-Agent instruction injection
Risk Level: High

Vulnerable Code

python
deliver_to_str = deliver_to or "<deliver_to>"
deliver_channel_str = (deliver_channel or "feishu").lower()
cmd = _run_task_command_shell(task, input_src, params_json, script_path)
is_video = _is_video_task(task)

if deliver_channel_str == "feishu":
    if is_video:
        delivery_instructions = (
            f"Download and send via Feishu: curl -sL -o /tmp/result.mp4 '<url>' && "
            f"python3 {base_dir}/scripts/feishu_send_video.py "
            f"--video /tmp/result.mp4 --to '{deliver_to_str}'"
        )
    else:
        delivery_instructions = (
            f"python3 {base_dir}/scripts/feishu_send_image.py "
            f"--image '<url>' --to '{deliver_to_str}'"
        )
elif deliver_channel_str == "telegram":
    if is_video:
        delivery_instructions = (
            f"Download and send via Telegram: curl -sL -o /tmp/result.mp4 '<url>' && "
            f"TELEGRAM_BOT_TOKEN=$TELEGRAM_BOT_TOKEN "
            f"python3 {base_dir}/scripts/telegram_send_video.py "
            f"--video /tmp/result.mp4 --to '{deliver_to_str}'"
        )
else:
    delivery_instructions = (
        f"Deliver to {deliver_to_str} via {deliver_channel_str}"
    )

return {
    "sessions_spawn_args": {
        "task": (
            f"Run: {cmd}\n\n"
            f"After completion, {delivery_instructions}\n\n"
            f"If failed with task_id, resume with: query-task --task-id <id>"
        ),
        "label": "kaipai: " + label,
        "runTimeoutSeconds": run_timeout_seconds,
    },
    "command": cmd,
}

Technical Analysis

Although _run_task_command_shell() applies shell quoting to the processing command, the ...[truncated 1821 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate recipients with platform-specific allowlists:
    • Feishu: accept only expected oc_... and ou_... identifier formats.
    • Telegram: accept only a signed decimal chat identifier.
    • Discord: accept only a decimal channel identifier.
  2. Restrict deliver_channel with an argparse choices allowlist.
  3. Apply shlex.quote() independently to every shell argument, including the recipient.
  4. Do not ask an Agent to reconstruct or interpret a shell command from prose. Pass structured command and argument arrays to a constrained execution tool.
  5. Keep untrusted values in structured fields separate from Agent instructions.
  6. Reject newline characters, control characters, shell metacharacters, and unexpected whitespace in recipient identifiers.
  7. Bind delivery to the authenticated inbound conversation rather than accepting an arbitrary destination whenever the platform permits this.

T09 · Insecure Skill Coding Practices

Error
Location
sdk/core/client.py:118
Finding

Unsigned Remote Configuration Can Redirect Signed API Requests and Media Uploads

Content
View full analysis

Vulnerability Details

File Location: sdk/core/client.py:118-138, sdk/core/api.py:346-366, sdk/core/api.py:432-465, sdk/storage/oss.py:84-125
Vulnerability Type: Unvalidated remote endpoint configuration
Risk Level: High

Vulnerable Code

python
def _fetch_config(self) -> Dict:
    """Fetch remote config and update local settings."""
    from sdk.core.config import VERSION

    try:
        gid = self._get_cached_gid()
        response = self.wapi.request(
            "/skill/config.json",
            method="POST",
            body={"gid": gid or "", "version": VERSION}
        )
    except RuntimeError as e:
        raise RuntimeError(f"Failed to fetch config: {e}") from e

    if response.get("gid"):
        self._cache_gid(response["gid"])

    if "algorithm" in response:
        algo = response["algorithm"]
        if "regions" in algo:
            self.api._config["regions"].update(algo["regions"])
            if self.api.region in algo["regions"]:
                self.api.EndPoint = algo["regions"][self.api.region]
        if "invoke" in algo:
            import sdk.core.config as sdk_config
            sdk_config.INVOKE.update(algo["invoke"])

    return response

The remote endpoint is then used for signed requests:

python
uri = f"https://{self.EndPoint}/ai/token_policy?type={typ}"
sign_request = signer.sign(uri, "GET", headers, "")
session = requests.Session()
resp = session.send(sign_request)

A policy returned from that endpoint controls the algorithm endpoint:

python
uri = policy["url"] + "/" + policy["push_path"]
sign_request = signer.sign(uri, "POST", headers, json.dumps(data))
session = requests.Session()
resp = session.send(sign_request, timeout=sync_timeout + 10)

The upload policy also controls storage credentials and destination:

python
creds = self.policy["credentials"]
credentials_provider =
...[truncated 2343 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS for every WAPI, algorithm, status, and storage endpoint.
  2. Allowlist exact approved API hosts or carefully validated organizational domain suffixes.
  3. Allowlist expected Alibaba OSS endpoint formats and reject arbitrary storage hosts.
  4. Reject URL user information, IP literals, nonstandard schemes, fragments, and unexpected ports.
  5. Validate push_path and status paths as relative paths and reject absolute URLs or traversal.
  6. Cryptographically sign configuration responses with a key pinned in the Skill package and verify signatures before applying changes.
  7. Validate remote configuration against a strict schema and fail closed on unknown fields.
  8. Consider pinning the algorithm endpoints in reviewed local configuration instead of allowing unrestricted replacement.
  9. Apply certificate validation normally and consider public-key pinning where operationally feasible.
  10. Document the remote configuration trust boundary and notify operators that media destinations can be changed remotely.

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Mandatory Dependency Installation Uses Unpinned Mutable Package Versions

Content
View full analysis

Vulnerability Details

File Location: scripts/requirements.txt:1-3, invoked by sdk/cli/commands.py:197-221 and mandated by SKILL.md:153-159
Vulnerability Type: Software supply-chain exposure
Risk Level: Medium

Vulnerable Code

text
alibabacloud-oss-v2>=1.2.0
pytest>=7.2.1
requests>=2.28.2
python
class InstallDepsCommand(CliCommand):
    """Install Python dependencies."""

    name = "install-deps"
    help = "Install requirements if needed"

    def execute(self, args: argparse.Namespace) -> int:
        req = Path(__file__).parent.parent.parent / "scripts" / "requirements.txt"
        if not req.exists():
            print(json.dumps({
                "error": "requirements.txt not found",
                "path": str(req),
            }))
            return 1
        try:
            import requests
            import alibabacloud_oss_v2
        except ImportError:
            r = subprocess.run(
                [
                    sys.executable,
                    "-m",
                    "pip",
                    "install",
                    "-q",
                    "-r",
                    str(req),
                ],
                cwd=str(req.parent),
            )
            return r.returncode
        return 0

Technical Analysis

Each dependency uses only a minimum-version constraint. Any future release satisfying that lower bound can be installed. No lockfile, hashes, trusted index selection, or isolated virtual environment is used.

Package installation may execute package build hooks with the privileges of the Agent process. The inclusion of pytest also expands the runtime dependency surface even though it is a test framework and is not required for normal Skill execution.

Attack Path

  1. A dependency publisher account, package release process, or configured Python package index is comp ...[truncated 702 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every runtime dependency to an exact reviewed version.
  2. Generate and verify cryptographic package hashes using pip's --require-hashes.
  3. Use a reproducible lockfile generated from a controlled build process.
  4. Remove pytest from runtime requirements and place it in a separate development requirements file.
  5. Install dependencies into a dedicated virtual environment rather than the Agent's global interpreter.
  6. Configure an explicitly trusted package index or internal mirror.
  7. Scan pinned dependencies for known vulnerabilities and establish a controlled update process.
  8. Avoid automatic installation during normal task execution where possible; provision dependencies during trusted deployment.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/kaipai_ai.py:42
Finding

Signed Media URLs and Task Metadata Are Persisted Without Explicit Access Controls

Content
View full analysis

Vulnerability Details

File Location: scripts/kaipai_ai.py:42-59, with sensitive record construction at scripts/kaipai_ai.py:82-111
Vulnerability Type: Insecure storage of sensitive task data
Risk Level: Low

Vulnerable Code

python
def _save_task_record(record: dict) -> None:
    """Save task record to state directory"""
    STATE_DIR.mkdir(parents=True, exist_ok=True)
    with open(LAST_TASK_FILE, "w", encoding="utf-8") as f:
        json.dump(record, f, indent=2, ensure_ascii=False)

    HISTORY_DIR.mkdir(parents=True, exist_ok=True)
    ts = datetime.now(timezone.utc).strftime("%Y%m%d_%H%M%S")
    hist_path = HISTORY_DIR / f"task_{ts}.json"
    with open(hist_path, "w", encoding="utf-8") as f:
        json.dump(record, f, indent=2, ensure_ascii=False)

    history_files = sorted(HISTORY_DIR.glob("task_*.json"))
    if len(history_files) > 50:
        for old in history_files[:-50]:
            old.unlink(missing_ok=True)

Sensitive values written to these files include:

python
record = {
    "saved_at": datetime.now(timezone.utc).isoformat(),
    "task_name": args.task,
    "input": args.input or "",
    "task_id": result.get("task_id"),
    "skill_status": "completed",
    "primary_result_url": result.get("primary_result_url"),
    "output_urls": result.get("output_urls", []),
}
_save_task_record(record)

Technical Analysis

Input and output URLs can contain signed query parameters that function as bearer credentials for media access. These values are retained in last_task.json and up to 50 history records.

The code relies on the process's ambient umask rather than explicitly creating the state directories and files with restrictive permissions. In an environment with a permissive umask, other local users or processes may be able to read the records.

The history uses a record-count retention rule but no time-based expiration or URL re ...[truncated 730 chars]

Remediation
View remediation

Remediation Suggestions

  1. Create STATE_DIR and HISTORY_DIR with mode 0700.
  2. Create or replace state files atomically with mode 0600, independent of ambient umask.
  3. Remove URL query strings before persistence, or redact known signature, token, credential, and expiry parameters.
  4. Store only the minimum fields needed for polling and recovery.
  5. Add a short time-based retention period in addition to the record-count limit.
  6. Provide a command to securely clear task history.
  7. Document that task history may contain sensitive media references.
  8. Avoid returning raw history to users unless authorization for the original conversation or tenant has been verified.
Vulnerability Patterns
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (111)

Tainted flow: 'token' from os.environ.get (line 31, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/notifications/telegram.py (reported line 54)May include surrounding context.

python
img_bytes = r.content
            filename = image_source.split("?")[0].split("/")[-1] or "image.jpg"
            files = {"photo": (filename, img_bytes, "image/jpeg")}
            resp = requests.post(
                f"{TELEGRAM_API_BASE}/bot{token}/sendPhoto",
                data=data,
                files=files,

Tainted flow: 'token' from os.environ.get (line 31, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/notifications/telegram.py (reported line 65)May include surrounding context.

python
return None, f"Image file not found: {image_source}"
            with open(image_source, "rb") as f:
                files = {"photo": (os.path.basename(image_source), f, "image/jpeg")}
                resp = requests.post(
                    f"{TELEGRAM_API_BASE}/bot{token}/sendPhoto",
                    data=data,
                    files=files,

Tainted flow: 'token' from os.environ.get (line 31, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/notifications/telegram.py (reported line 125)May include surrounding context.

python
except Exception as exc:
                    print(f"[telegram] Thumbnail download error: {exc}, skipping", file=sys.stderr)

            resp = requests.post(
                f"{TELEGRAM_API_BASE}/bot{token}/sendVideo",
                data=data,
                files=files,

Tainted flow: 'token' from os.environ.get (line 31, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/notifications/telegram.py (reported line 151)May include surrounding context.

python
"""Send plain text message."""
        token = self._get_token()
        print("[telegram] Sending text message", file=sys.stderr)
        resp = requests.post(
            f"{TELEGRAM_API_BASE}/bot{token}/sendMessage",
            json={"chat_id": chat_id, "text": text},
            timeout=(CONNECT_TIMEOUT, 30),

Tainted flow: 'token' from os.environ.get (line 660, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · sdk/cli/commands.py (reported line 665)May include surrounding context.

python
_print_json({"error": "TELEGRAM_BOT_TOKEN not set"})
            return None, ""

        r = requests.get(
            f"https://api.telegram.org/bot{token}/getFile",
            params={"file_id": file_id},
            timeout=(15, 60),

Tainted flow: 'dl_url' from os.environ.get (line 687, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · sdk/cli/commands.py (reported line 688)May include surrounding context.

python
filename = f"tg_{uuid.uuid4().hex[:8]}.{extension}"

        dl_url = f"https://api.telegram.org/file/bot{token}/{file_path}"
        r2 = requests.get(
            dl_url,
            timeout=(15, 120),
            headers={"User-Agent": "kaipai-ai-sdk/1.2.2"},

Tainted flow: 'feishu_token' from os.environ.get (line 713, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · sdk/cli/commands.py (reported line 719)May include surrounding context.

python
return None, ""

        url_to = url_download_timeout_tuple()
        r = requests.get(
            f"https://open.feishu.cn/open-apis/im/v1/messages/{message_id}/resources/{image_key}",
            params={"type": "image"},
            headers={"Authorization": f"Bearer {feishu_token}"},

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

As with the earlier arbitrary-task report, exposing execution of undocumented task names broadens the authority of the skill beyond what reviewers and users expect. That can enable misuse of tenant quota or access to risky backend operations under trusted credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.