Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 92% confidence
- Finding
- The documented behavior does not fully match the implemented behavior: local persistence is omitted from the high-level description, and the default exchange reportedly differs from the stated default. This can mislead users about where data is stored and which external service receives requests, undermining informed consent and creating operational/security risk if users trust the documentation.
