Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
- The skill’s declared purpose is branch renaming for history preservation, but the documented behavior also performs network and state-changing remote operations, including pushing renamed refs and deleting the old remote branch name. That mismatch is dangerous because users or higher-level agents may invoke it assuming a local, non-destructive rename, when it can actually alter shared repository state and remove a remote ref.
