Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
- A second independent mismatch report says the code lacks any actual network scanning or fingerprinting logic while performing file writes, directory creation, and cross-agent installation based on HOME/CODEX_HOME/XDG paths. A security skill that claims to be read-only reconnaissance but instead modifies local state is especially dangerous because it can evade scrutiny under the cover of legitimate security tooling.
