Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
- This mismatch is security-relevant because the skill presents itself as a conversational workflow aid while also instructing the agent to initialize local state and potentially edit ignore-related repository files. Undisclosed repository modifications and subprocess use can surprise users, alter project state, and create an opportunity for unsafe command execution in contexts where only advisory behavior was expected.
