Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
If the implementation only validates a token and prints console/marketing output, then the README's claims about transcription, summarization, translation, and privacy are materially false. While less directly exploitable than arbitrary file/network access, this still undermines user trust and can be used to collect tokens, drive users to off-platform contact channels, or bypass proper security review through misleading metadata.
- Content
