Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
If the implementation performs local filesystem writes that are not disclosed in the skill description, that is a meaningful security concern because users and hosting agents may authorize a read-only analytics skill while it modifies local state. Undocumented write capability can enable data tampering, persistence, or accidental leakage through generated files, especially in automation environments that trust the declared behavior.
- Content
