Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The skill is described as a query-only Rain Classroom helper, but the documentation also covers MCP server registration, secret-based connection setup, installation verification, and mentions install telemetry being reported remotely. This mismatch weakens informed consent: users may authorize or install a skill believing it is read-only while it also performs setup and external reporting behaviors not clearly disclosed in the primary description.
