Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The documented behavior includes an `evaluate` action that executes arbitrary JavaScript in the browser context, and the finding indicates additional behaviors such as visiting a specific third-party site, checking login state, attaching to an existing local Chrome debug port, and writing screenshots locally. Those capabilities go beyond a simple browser automation description and materially increase risk because they can interact with authenticated sessions, inspect user data, and perform actions on external sites without sufficiently explicit disclosure or constraints.
