Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill advertises QuickBooks business-context usage, but the documented behavior includes credential seeding, persistence to a shared local vault, and use of a generic MCP wrapper rather than a narrowly scoped QuickBooks implementation. That mismatch is security-relevant because operators may approve or invoke the skill expecting read/write accounting actions only, while it also handles OAuth secrets and shared credential state, increasing the chance of unintended token exposure, privilege creep, or misuse of generic tooling.
