Skip to content

Hide Navigation Hide TOC

Skill Description-Behavior Mismatch - ATR-2026-00061 (96d6666a-7555-52b2-9898-672b86a49a4c)

Detects MCP skills whose runtime behavior diverges from their declared description. A skill described as "read-only file browser" that issues write or delete operations, or a "weather lookup" tool that accesses filesystem or network resources beyond its stated scope. This is a supply-chain indicator: a compromised or trojaned skill may retain its benign description while performing malicious actions.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Meta Prompt Extraction (e98acce8-ed69-4ebe-845b-1bcb662836ba) MITRE ATLAS Attack Pattern Skill Description-Behavior Mismatch - ATR-2026-00061 (96d6666a-7555-52b2-9898-672b86a49a4c) Agent Threat Rules 1
Skill Description-Behavior Mismatch - ATR-2026-00061 (96d6666a-7555-52b2-9898-672b86a49a4c) Agent Threat Rules ML Supply Chain Compromise (d2cf31e0-a550-4fe0-8fdb-8941b3ac00d9) MITRE ATLAS Attack Pattern 1