Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 83% confidence
- Finding
- The top-level description is overly focused on 'explicit permission disclosure for security audit' and does not clearly summarize the skill's actual operational behavior, which includes reading session history, generating persistent artifacts, and invoking local execution/inference tooling. That mismatch can mislead users or reviewers about the real data-handling and execution scope, increasing the chance that sensitive session content is exported or processed without fully informed consent.
