Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The manifest and description frame the skill as routine browser automation, but the documented capabilities materially exceed that scope by exposing arbitrary JavaScript execution, arbitrary Playwright code execution, and a persistent local control daemon. This mismatch is dangerous because downstream agents or users may grant trust and invoke the skill under a narrower risk assumption than its actual authority, enabling stealthier data access, page manipulation, and local browser control.
