Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The declared purpose narrows the skill to local-model rewriting, but the documented and inferred behavior appears substantially broader, including scanning, deterministic file modification, hook handling, PR/commit message rewriting, DOCX parsing, SARIF emission, and prompt-injection detection. This mismatch is dangerous because operators may approve or invoke the skill under a limited trust assumption while it actually has broader automation and content-processing reach, increasing the chance of unintended file changes, network use, or workflow integration in sensitive environments.
