Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill advertises embeddable React/HTML components, but the documented behavior includes shell execution, raw JSON/CLI output, and outbound calls to a remote PRISM service. This mismatch can mislead users and agents into granting trust or integrating the skill under false assumptions, increasing the risk of unexpected code execution paths and unreviewed data exfiltration or supply-chain exposure via remote dependencies.
