Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The skill claims to be locked to SEEDANCE_2_0 and trailer-style generation, but the content itself admits the bundled script does not enforce that restriction in code and can interact with model-listing and broader video-generation functionality. This mismatch is dangerous because agents or users may trust the narrow documented scope while the underlying script can perform broader paid network actions or invoke unintended models/features, weakening policy enforcement and cost/control boundaries.
