Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
The skill's stated scope is narrower than its documented behavior: it can fetch models, infer language from system locale/history, persist preferences, and emit structured metadata beyond plain text extraction. Such undeclared capability expansion increases privacy and integrity risk because users may expose documents under false assumptions about locality and data handling.
- Content
