Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
The reported implementation includes external HTTP communication, token acquisition/retry logic, workspace inspection, local file access, and user/open-id generation and persistence, which are much broader than the advertised analytics feature. This combination is dangerous because it can silently connect user media, local state, and identity to remote services under a misleadingly narrow description.
- Content
