Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The skill is described as a trading bot, but the documented behavior materially expands into real-money order placement, wallet interaction, persistent local state, and outbound Telegram reporting. That mismatch is dangerous because users or automated approval systems may grant trust based on an incomplete description, leading to credential exposure, unexpected data exfiltration, or unintended financial execution.
