Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill claims local ZIP-based installation into the current workspace, but the documented behavior relies on a remote center service and transmits a real userId along with AppKey-derived authentication context. This mismatch is dangerous because users and downstream agents may believe installation is a local, constrained action when it actually triggers privileged remote operations and data disclosure to an external service.
