Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The primary purpose broadly aligns with searching Substack via browser automation, but the declared description overstates the structure and formatting of the output. The code opens Substack search pages and scrapes visible link text, which is consistent with Substack search scraping. However, it does not explicitly extract titles, authors, and summaries as separate fields, nor does it produce a numbered digest. Instead, it gathers long link text blobs from browser snapshots, deduplicates them, and prints a JSON list. That is a material description-to-behavior mismatch in capability and output format, though not a wholly different purpose.
