Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
The documented scope is narrow operational monitoring, but the code indicators include external HTTP communication, authentication/token handling, automatic account creation/login, workspace discovery, and local identity persistence. These capabilities materially increase attack surface and privacy risk because they enable remote service interaction and durable user correlation under a misleading label.
- Content
