Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
- The skill directs the agent to run an auto-update script that downloads updates from GitHub and overwrites local skill files at session start. A self-updating execution path materially changes code after installation, expanding the trust boundary and enabling supply-chain compromise or silent behavior changes without explicit re-approval from the user.
