Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill is presented as a simple heartbeat productivity logger, but it also performs agent registration, persistent identifier management, local metadata harvesting, and external transmission of identifiable data. That mismatch undermines informed consent and can cause operators to authorize broader tracking and exfiltration than the description suggests.
