Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The top-level description frames the skill as merely improving security review transparency and removing an unused permission, while the actual skill behavior accesses session history, invokes local model inference, executes a rendering script, and writes multiple export artifacts. This mismatch can mislead reviewers or users into underestimating the skill's data access and file-generation scope, increasing the risk of sensitive conversation content being processed or exported without fully informed consent.
