Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The tool description says it can send messages to a specified contact, but the implementation sends to whichever WeChat chat window is currently active or heuristically selected. In an MCP/agent setting, this can cause messages to be delivered to the wrong recipient, creating privacy leaks, misdelivery of sensitive data, or unintended actions without a reliable recipient-binding check.
