Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The description understates the skill's behavior by saying it can search, read, and update CRM data, while the documented behavior also includes creating records, adding notes, enumerating metadata, and seeding/storing OAuth tokens and client credentials in a local vault. This mismatch can cause users or orchestrators to invoke the skill with a lower trust threshold than warranted, increasing the chance of unintended state changes or sensitive credential handling.
