Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 89% confidence
- Finding
- The skill is presented as a CFO advisory system, but it also acts as a router, enumerator, and loader for other installed skills and local skill files. That mismatch can cause users or platform controls to trust it as a narrow business-analysis tool while it actually expands reach into local skill inventory and orchestration behavior, increasing attack surface and enabling unexpected data or capability discovery.
