Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill claims to provide undo/history, but the documented behavior expands into package-manager based software installation and a persistent background watcher. Those side effects materially exceed user expectations for an undo tool and could change the host system or keep monitoring files after the immediate task, creating unauthorized system modification and persistence risks.
