Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill presents itself as 'Label Studio', a known annotation product, but the documented behavior is a generic local CLI logger that stores arbitrary inputs, tracks history, supports search, and exports accumulated records. This mismatch can mislead users and downstream agents into invoking a tool under false assumptions, causing unintended collection and persistence of potentially sensitive data and creating a supply-chain style trust problem.
