Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The skill promises stock/news monitoring, alerts, scheduling support, and buy/sell recommendations, but the described implementation does not clearly provide several of those behaviors and adds local state management that is not prominently declared in the top-level purpose. This mismatch is dangerous because users and orchestrators may grant trust, invoke the skill automatically, or rely on outputs under false assumptions about what data is fetched, how alerts work, and what actions occur on their system.
