Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill description frames the capability as project analysis and showcase generation, but the body instructs the agent to scan arbitrary project directories, enumerate filesystem structure, read README/package metadata, inspect config files including .env/application.yml, and parse user-provided local documents. That expands the data-access surface beyond what the top-level description transparently discloses, creating a meaningful risk of over-collection of sensitive local information such as secrets, internal paths, dependency metadata, and resume contents.
