Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
If the actual code does not perform the promised Douyin queries and instead accesses local files or package metadata, the skill's declared trust boundary is inaccurate. This is risky because operators may route user tasks and secrets to the skill expecting a constrained external-data workflow, while the real implementation can interact with the local environment in unexpected ways.
- Content
