Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- This is a mismatch because the declared purpose says the skill operates NEAR JSON-RPC reads through UXC, implying runtime behavior for interacting with a NEAR provider. The actual code shown does not perform any NEAR JSON-RPC calls, provider selection, or read-only request handling. Instead, it statically validates that certain files exist and contain expected strings and schema entries. That is a materially different primary purpose from the description.
