Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The server exposes a third capability, tiandao_whisper, that lets the MCP client inject messages into the game world, which is broader than the stated register/perceive/act TAP interface. Capability drift matters in agent tooling because users and orchestrators may grant trust based on the declared interface, while the extra messaging primitive can be used to steer agents, manipulate world state, or create an unintended human-to-agent control channel.
