Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
Repeated description-behavior mismatch findings indicate the skill's documented purpose materially diverges from its implementation. Even without obviously malicious code, this creates a trust-boundary problem: reviewers cannot rely on the manifest to understand what will execute, what data will be accessed, or whether external requests are truly necessary. Such ambiguity is a real security issue for agent ecosystems because policy, routing, and user consent are often based on manifest text.
- Content
