Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
- The skill advertises a local RAG workflow, but the provided instructions explicitly install and rely on code fetched from a remote GitHub repository at runtime rather than implementing or vendoring the behavior locally. That creates a supply-chain and trust-boundary issue: users may believe they are running a transparent local-only skill, while in practice they execute unreviewed upstream code and an external engine path not clearly disclosed as core behavior.
