Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
If the skill performs local filesystem writes such as creating log directories and saving content while claiming it is read-only and 'does not upload any local files' with 'no write operations,' that is a meaningful trust-boundary violation. Users and orchestrators may grant the skill broader trust based on the documented read-only posture, while the implementation persists data locally, potentially including scraped content, links, or sensitive prompts.
- Content
