Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
There is a clear description-behavior mismatch. The declared purpose says the skill should be used when a user provides an architecture diagram and wants infrastructure or component code generated. However, the supplied code chunk contains only automated tests for skill packaging/documentation compliance. Its primary function is QA/linting of a skill repository, not diagram interpretation or code generation. The file access patterns are also inconsistent with the declaration: it reads SKILL.md, README.md, tests/, scripts/, and scans local files for secrets rather than consuming user diagrams or emitting IaC/component code. This is not a supporting implementation detail; it is a materially different primary purpose.
- Content
