Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The documented behavior says the skill runs at session end to summarize and store memory, but the finding indicates it also supports manual bulk processing, a daily cron job, and enumeration of recent closed sessions. That expands the collection scope from a single end-of-session action to retrospective and scheduled processing, which can capture more user data than expected and undermine informed consent and operator oversight.
