Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The skill presents itself as a local RAG helper, but the documented install path pulls and runs code directly from a remote GitHub repository (`git+https://...@main`) and relies on external components whose behavior is not visible in this skill file. That creates a supply-chain and transparency risk: users may trust the skill as a simple local data tool while it executes unpinned third-party code and uses a default external engine, which could change over time or handle sensitive documents in unexpected ways.
