Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The documentation claims broader provider coverage and an OpenAI-compatible gateway, while the described behavior is closer to a client wrapper for a specific remote service and includes undeclared comparison functionality. Security-relevant behavior mismatches reduce informed consent and can cause users to send prompts, credentials, or workload patterns under false assumptions about where data goes and what the skill does.
