Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The skill claims start/stop/status control of a ComfyUI instance, but the observed behavior only probes a health endpoint over HTTP and does not implement the promised run/stop actions. This mismatch is security-relevant because operators may authorize the skill under false assumptions, and hidden or incomplete behavior reduces auditability and can mask future capability creep or unauthorized network interactions. In this context, the discrepancy is more dangerous because the skill targets a specific internal IP and may be used in automation where accurate capability declaration is important.
