Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill advertises itself primarily as a logging/improvement aid, but the body also instructs users to install hooks, inject reminders into agent context, scan tool failures, and generate new skill scaffolds. This mismatch is security-relevant because operators may approve a seemingly harmless memory skill without realizing it changes runtime behavior and writes additional files.
