Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The documented purpose understates several behaviors with security relevance, especially auditing arbitrary HTML files, exporting interfaces for external consumption, and generating QR codes via an external web API despite claims of no external network access. This mismatch can cause operators to grant trust or permissions under false assumptions, increasing the chance of unintended data exposure or processing of untrusted files.
