Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
The manifest claims anonymized, limited-purpose emotional monitoring, but the visible implementation includes filesystem access, environment discovery, reading local identity/credential files, persistent user creation, remote authenticated API access, and token storage. In an employee surveillance context, that combination is highly sensitive and materially expands the risk of identity linkage, credential exposure, and off-manifest data processing.
- Content
