Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 88% confidence
- Finding
- The skill advertises backup/restore to Google Drive and disaster recovery coverage, but the documented behavior does not show the claimed backup implementation and also appears to introduce sensitive key-management actions not clearly disclosed. This mismatch can mislead operators into trusting incomplete recovery guarantees or unexpectedly creating/restoring secrets, which is dangerous in infrastructure automation where omissions or hidden state changes can cause outage, lockout, or credential mishandling.
