Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
If the implementation truly performs local filesystem writes, directory creation, and content saving while the skill markets itself as a read-only external data tool, that undisclosed side effect creates avoidable risk. Hidden local writes can store sensitive query data, create persistence artifacts, or be abused for unexpected disk usage and privacy violations, especially because the skill handles user-supplied keywords and links sent to a third-party API.
- Content
