Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The documented behavior does not cleanly match the stated purpose: the skill also supports image-to-video, task-status polling, and local file storage, while the claimed 'auto-send to chat' behavior appears undocumented or unsubstantiated. This can mislead users about what data is stored, what external resources are contacted, and what content may be shared, undermining informed consent and safe use.
