Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill is described as a design/brainstorming aid, but it also instructs use of a browser-based 'visual companion' and references additional behavior that can include local server orchestration, browser interaction, and event transmission outside the declared scope. Hidden or under-declared operational behavior is dangerous because users may consent to a harmless-seeming planning skill while actually enabling interactive tooling with broader access to local resources and user activity.
