Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
The declared description promises a full-featured multi-platform publishing capability, including timed posting, format conversion, one-click dispatch, and publish logging across several external platforms. However, this code chunk only loads configuration from WORKDIR/skill_config/zd_publish_rule.yaml and prints a summary of platform rules to stdout. It explicitly says real publishing should be done via another script, indicating this file is informational rather than operational. There is no evidence of outbound platform publishing, scheduler logic, transformation/formatting logic, or persistent logging. Therefore, the supplied code chunk materially underdelivers relative to the declared purpose, so this is a clear description-behavior mismatch.
- Content
