Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The documented behavior and the static analysis summary indicate multiple bypass paths that undermine the core safety promise of the skill: global disablement, auto-confirmation in non-interactive mode, context-driven downgrades, and direct execution of pending commands. If the implementation also uses eval, an attacker or prompt-injected agent could expand execution scope and run arbitrary shell payloads without the intended human review boundary.
