Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill's declared purpose is narrow, but the content introduces additional capabilities such as hook-triggered automation, cross-session coordination, and skill extraction. This matters because operators may trust and enable it as a harmless note-taking utility while actually granting it broader persistence and automation behavior than advertised.
