Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The documented behavior materially overstates and misrepresents what the skill does, including claims around telephony, transcription, and authentication. Most importantly, if the implementation accepts any auth token and only logs invalid tokens instead of rejecting requests, unauthorized parties could interact with the bridge, access memory-backed context, or trigger storage/logging paths.
