Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 87% confidence
- Finding
- The skill description frames the feature set as memory/search functionality, but the reported behavior includes activation key storage, installation checks, and local status probing of files like activation.json and memory.db. That mismatch is security-relevant because users may grant trust to a memory skill without realizing it also inspects environment state and local filesystem artifacts; the 'skill is safe' language in the file further increases suspicion rather than reducing it.
