Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
The skill advertises broad, structured, citation-backed research, but the implemented behavior is limited to a small set of shell-based lookups and raw result fetching. This mismatch is security-relevant because operators may overtrust the skill’s outputs and permissions profile, while hidden implementation limits and subprocess behavior can cause unsafe delegation, inaccurate conclusions, or misuse in contexts expecting controlled report generation.
- Content
