Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
- The code substantially matches part of the declared purpose: it does repair missing SKILL.md sections for 功能描述 and 使用示例. However, two declared capabilities are absent. First, although the code can parse frontmatter boundaries, it never inspects, adds, or repairs the claimed frontmatter fields (version/author/changelog/metadata). Second, the description says it supports batch repair of an entire skills directory, but the CLI accepts a single skill path and processes only one SKILL.md at a time. These are material omissions from the declared functionality, so the description does not accurately represent the actual behavior.
