Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 94% confidence
- Finding
- The skill metadata and repeated trigger guidance say it should only activate when the user explicitly specifies a design style, but the documented bundled scripts also enable smart inference, random style selection, and copying files into the working directory. That mismatch can cause unintended execution paths and side effects, especially if an agent relies on the description for safety boundaries and then invokes behavior that selects or writes files without clear user intent.
