Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The skill claims full lifecycle context management, but the described behavior includes extracting 'decisions/findings/issues/plans' from user/assistant messages and injecting them into the system prompt. That is a trust-boundary violation: untrusted conversational content can be elevated into higher-priority instructions or durable context, enabling prompt-injection persistence, policy contamination, or incorrect agent steering across later turns.
