Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill markets itself as a proactive-agent architecture, but it also instructs users to run a local security audit script and the static finding indicates broader auditing behavior than the description discloses. That mismatch is dangerous because users may install or trust the skill for productivity features while overlooking security-relevant file inspection behavior, reducing informed consent and increasing the chance of overbroad local data access.
