Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The documented behavior goes beyond image generation by directing the runtime to source secrets from TOOLS.md, which implies local file inspection for credentials not reflected in the high-level description. This mismatch is dangerous because users may authorize an image tool without realizing it can traverse local configuration files and harvest API keys from hardcoded locations, increasing secret-exposure risk.
