Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
The code’s behavior is narrower and materially different from the declared description. It is a summarizer over an already collected bundle, not a live Etherscan-backed transaction analysis skill. It performs useful transaction summarization tasks consistent with part of the description—status, fees, some token events, native movements, and warnings—but it lacks several core declared capabilities: no network/Etherscan access, no evidence-link generation, no plain-English explanatory output, no full execution-path reconstruction, no proxy analysis, and no detailed revert-site identification. This is more than an implementation detail because the declared primary purpose emphasizes live Etherscan investigation and explanatory evidence-based analysis, while the code is an offline post-processing component.
- Content
