Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 93% confidence
- Finding
- The skill description understates the real operational scope: beyond signal generation, it can discover/import markets, monitor positions, execute exits, persist configuration, and perform live trading with an additional private key. In a trading skill handling high-value credentials, this mismatch can mislead users into granting trust and secrets they would not provide if the full behavior were clearly disclosed, increasing the chance of unintended live trades or broader account interaction.
