Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 88% confidence
- Finding
- The skill description understates materially sensitive behavior: it not only ranks models and edits config, but also performs live API probing and offers a long-running watcher that can continuously make network requests and rewrite configuration. Users may consent to a one-time config helper without realizing they are enabling persistent autonomous behavior, which increases the risk of unexpected traffic, instability, or unintended changes.
