Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The skill claims to help discover bargain flights through live analysis, but the documented local tooling only performs static route lookup and QR code generation while relying on an external CLI for flight search. This mismatch can mislead reviewers and users about what is actually executed and what third-party components/processes handle sensitive travel queries, reducing transparency and informed consent.
