Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 90% confidence
- Finding
- The metadata and description present the skill as a narrow self-repair utility, but the documented behavior includes broad capabilities such as arbitrary LLM prompting, routine scheduling, custom routine execution, and generic process management. This scope mismatch is dangerous because it can cause users or downstream systems to grant trust and permissions appropriate for diagnostics while the skill can perform far more powerful actions affecting processes, commands, and system behavior.
