Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
The code largely matches the declared Spotify data access purpose: it is restricted to Spotify-related endpoints for albums, artists, artist top tracks, playlists, search, and tracks. However, there is a small description-behavior mismatch in scope/wording. The implementation exposes only six specific allowlisted paths and only one 'top tracks' capability, namely artist-top-tracks, rather than any broader top-tracks functionality. Also, the description's 'catalogue search' wording is somewhat broader than the explicit allowlist, which only includes a single /v1/spotify/search endpoint. There is no evidence of unrelated behavior, extra resource access, or undeclared sensitive capability; the mismatch is minor but present.
- Content
