Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- Most of the code matches the declared description: it computes BaZi pillars, analyzes Five Elements, performs zodiac matching, and analyzes Chinese names. However, the repository also contains a separate verify.py script that performs software release verification by reading local metadata files and spawning subprocesses to test outputs. That behavior is not mentioned in the declared purpose and is unrelated to the stated cultural/entertainment metaphysics tool functionality. Because the evaluation rules say to flag any undeclared capability, this should be marked as a mismatch, even though the main user-facing functionality is accurately described.
