Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The documented behavior understates materially sensitive capabilities: live trading scaffolding, billing-management endpoints, and especially the note that code may use a hardcoded external SkillPay API key. Misleading or incomplete disclosure can cause users or integrators to invoke a skill with financial side effects or trust boundaries they did not consent to, and a hardcoded credential would create direct secret-exposure risk if present in code.
