Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The declared purpose is resume screening, but the workflow also performs local PDF extraction, text cleaning, quality scoring, backend comparison, and writes extracted candidate data to disk. That mismatch matters because resumes contain sensitive personal data, and users may not realize the skill is transforming and persisting files beyond simple evaluation, increasing privacy and data-handling risk.
