Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The documentation claims the skill is limited to local or saved HTML files, but the described behavior indicates the injected editor can operate on whatever DOM it is inserted into and auto-start by default. That scope mismatch is dangerous because it can enable editing or exporting content from arbitrary live pages, potentially including sensitive authenticated pages, violating user expectations and the stated safety boundary.
