Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
The code chunk does not itself implement the skill runtime; it is a test file for that implementation. However, judged by behavior exercised and asserted, it largely aligns with the declared purpose: it covers the four I/O commands (
fetch,content,submit,report), bearer-token gateway use, body-read cap of 12, always-report behavior including empty fetches, and server-side ownership of outcome fields. The main mismatch is that this chunk also enforces additional responsibilities not disclosed in the description: documentation-wire-contract validation, CLI/exit-code semantics, and detailed markdown sanitization/report rendering rules. These are material capabilities of the tested bundle but ancillary to the core email-triage purpose. So there is a mismatch, though it is more an under-description of supporting/contract-enforcement behavior than a completely different primary purpose.- Content
