Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 99% confidence
- Finding
- This is a mismatch because the declared description claims end-user Canva functionality through a hosted MCP server, but the provided code does not implement any Canva design, asset, folder, export, brand, comment, or template operations. Instead, it is purely setup infrastructure for seeding OAuth credentials into mcporter's vault based on environment variables and config. While that may support connecting to an MCP server, the actual code shown is not a thin runtime pass-through to Canva's MCP and its primary purpose is materially different from the description.
