Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
The declared description is for a post-run auditing/consolidation skill that should collect artifacts from SWMM runs and produce auditable provenance, comparison records, and Obsidian notes tied to specific executions. The provided code instead only bootstraps a local Obsidian vault structure with static folders, configuration, and template notes. While this supports the broader auditing ecosystem, it is not the described core behavior. There is no logic to inspect runs, read inputs/commands/artifacts, compute metrics or diffs, or emit run-level provenance/comparison outputs. Therefore the code's actual purpose is materially different from the declared purpose.
- Content
