Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- If the implementation performs local filesystem writes, directory creation, and saves arbitrary string content while the skill is documented as a read-only public-data tool, that creates a meaningful trust-boundary violation. Hidden write behavior can be abused for local data persistence, log poisoning, workspace pollution, or dropping attacker-controlled content in unexpected paths, especially when users expect no local side effects.
