Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The skill claims it avoids leaving plaintext keys on disk, but its described behavior injects secrets into a LaunchAgent plist, which is itself a file persisted on disk. If it also writes OP_SERVICE_ACCOUNT_TOKEN into the plist, it converts a high-value credential into a persistent local secret, broadening compromise impact to anyone or any process that can read the plist or backups of it.
