Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The manifest and description present this as a financial valuation skill, but the documented behavior is actually a generic local logger that stores arbitrary input, supports search, and exports accumulated data. This mismatch is dangerous because users may provide confidential valuation assumptions, company financials, or board-sensitive notes expecting modeling functionality, while the skill instead persists that data in plaintext and broadens exposure through history, search, and export features.
