Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The skill advertises AI-powered JSON/YAML validation, conflict detection, and best-practice guidance, but the analysis indicates it only performs basic JSON parsing and undeclared local file reads. This mismatch can mislead users into exposing sensitive configuration files under false assumptions about capability and safety, especially when .env or other secret-bearing files are involved.
