Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- If the implementation downloads theme assets from a public host such as `daytrading.monster` and writes refreshed local cache files, while the skill presents itself as relying on MX and approved aggregate sources, that is a supply-chain and trust-boundary problem. Operators and users may assume data provenance and network exposure are limited to sanctioned providers, but the hidden external dependency can inject untrusted content into local caches and influence later analysis. In a financial-data skill, provenance errors materially increase the risk of manipulated outputs.
