Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The skill markets itself as an offline local chat UI, but the documented behavior includes arbitrary local file ingestion triggered by model output and outbound connectivity checks to an external site. This mismatch can cause users to trust the tool with sensitive data under a false assumption that it only talks locally, increasing the chance of unintended disclosure.
