Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill description emphasizes purchasing governed outcomes, but the body also instructs the agent to perform local setup actions, run a bootstrap script, configure an MCP server, initiate OAuth, and handle a localhost callback URL. That mismatch is security-relevant because it can cause a user or calling system to authorize installation/configuration and credential-handling behavior they did not reasonably expect from the declared purpose, increasing the chance of overbroad trust and unsafe execution.
