Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill claims to analyze favorite Youdao notes and push relevant news, but the documented workflow also sends derived user-interest queries to third-party search providers and relies on external tools not clearly disclosed in the user-facing purpose. That mismatch matters because note-derived topics can reveal sensitive interests, and users may not expect their note content to influence outbound searches or scheduled automation.
