Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill is presented as desktop automation, but the documented behavior expands into broader sensitive capabilities such as window enumeration/activation, clipboard read/write, simulated application launching, and semi-autonomous workflows. This mismatch reduces informed consent and can cause operators to enable a skill without realizing it can access sensitive on-screen data, manipulate other applications, or trigger unintended actions.
