Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The skill is presented as an Instagram-specific analysis workflow, but the documented runner supports generic remote tool enumeration, schema inspection, multi-platform operation, and arbitrary tool execution against an external MCP server using the user's bearer token. That broader capability increases the attack surface: a user expecting narrow Instagram analysis could instead authorize actions or data access beyond the advertised scope, especially if the remote server exposes additional tools.
