Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The skill claims to provide automatic Feishu voice replies via built-in messaging, but the documentation primarily describes local MP3 generation, package installation, and hypothetical message-tool usage without demonstrating the actual Feishu reply flow. This mismatch is dangerous because users may grant trust, install dependencies, or rely on automation assumptions that are not actually implemented, increasing the chance of unsafe deployment, hidden functionality in omitted files, or operational misuse.
