Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The declared description centers on operational use of the Stripe CLI for development and sandbox testing workflows. The actual code does not invoke the Stripe CLI, manage webhooks, trigger events, inspect API requests, or perform sandbox resource management. Instead, it sanitizes logs or text by masking Stripe-related secrets. While this is Stripe-related and could support safe log handling, it is a materially different primary purpose that is not represented in the description.
