Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The documented skill purpose is image selection and message sending, but the static finding indicates additional behavior that can overwrite IDENTITY.md, modify SOUL.md, and alter agent workspaces. Hidden persona/workspace modification is dangerous because it can permanently change agent behavior and persistence boundaries beyond the user's expected action.
