Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 88% confidence
- Finding
- The skill presents itself as a persona-distillation workflow, but it also documents filesystem management, rollback/versioning, runtime installation/switching, SQLite extraction, and training/export pipelines that materially expand what it can do. This mismatch is dangerous because users may consent to a narrow purpose while the skill performs broader data handling and environment-modifying actions than expected.
