Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The manifest and top-level description frame this as a generic climate tool for 'everyday use,' but the documented behavior includes persistent local storage, activity logging, history tracking, search, and export of stored data. That mismatch can cause users or orchestrating agents to invoke the skill without understanding that it retains and republishes potentially sensitive user-provided data, increasing privacy and data-handling risk.
