Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill description frames behavior as passive logging and review, but the body also instructs hook-based automatic reminders, cross-session sharing, and creation of new skill scaffolds. That mismatch can cause users or agents to enable broader persistence and automation than they reasonably expected, weakening informed consent and increasing the chance of unintended data retention or prompt-surface expansion.
