Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 88% confidence
- Finding
- The skill’s declared behavior materially differs from the analyzed implementation: it reportedly stores score and streak data locally while advertising mainly harmless trivia features, and it claims category selection and group competition that are not actually implemented. This is dangerous because users may grant trust or deploy the skill under false assumptions about data handling and functionality, which can lead to unexpected persistence of user data and misleading security/privacy expectations.
