Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The skill claims broad video-performance analysis using visual analysis and metrics, but the provided implementation mainly sends URLs to a third-party transcript API and evaluates word count, with additional spreadsheet processing beyond the headline description. This mismatch can mislead users about what data is processed and shared, increasing the risk of unintended external transmission and overbroad invocation in contexts where sensitive creator data or performance spreadsheets are involved.
