Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The skill claims to be a narrowly scoped Grok crypto-research tool, but the documented behavior forwards arbitrary user input to an A9-hosted endpoint, allows model overrides, and uses inconsistent credential naming. That mismatch is dangerous because users and reviewers may trust the skill with sensitive prompts under false assumptions about destination, scope, and provider, increasing the risk of unauthorized data disclosure and misuse.
