Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 86% confidence
- Finding
- The declared purpose focuses on interacting with a Zotero library, but the documented helper scripts expand into installation, backup/restore, update checks, browser opening, and file deletion behaviors. This mismatch is dangerous because users or agent frameworks may grant trust appropriate for a read/write bibliography tool, while the skill also performs broader filesystem and network actions that increase the attack surface and can lead to unintended changes on the host.
