Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
The skill advertises a bounded profile-sync workflow, but its stated behavior includes reading arbitrary manifest-selected files from the user's home directory and uploading only the first readable entry, while declared permissions include broader write and network capabilities. That mismatch is dangerous because users and reviewers may authorize the skill under false assumptions, enabling unintended exfiltration of local files selected by a remotely controlled manifest.
- Content
