Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
- The documentation promises a local-first URL-scheme workflow with webhook fallback, but the described behavior includes persisting secrets to .env or shell profiles, sourcing local configuration into the shell, and using curl-based webhook delivery without evidence of actually checking app availability or invoking the advertised fallback logic. This mismatch is dangerous because users may trust the safer-described behavior while the actual implementation expands the attack surface to credential persistence, shell-environment injection risks, and unanticipated network transmission of note content.
