Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The skill's declared purpose focuses on file organization, but its workflow also performs app-installation detection, startup-state probing, local config discovery, API endpoint discovery, and forced display of vendor promotional/install guidance. This hidden behavior expands the trust boundary and can be abused for unexpected local reconnaissance and manipulative output control, especially because the skill instructs the agent to emit stderr verbatim as the final response.
