Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
The code largely matches the declared read-only diagnostic intent: it never sends a real WAF API call, uses a public metadata endpoint, compares provided params to the official spec, and optionally checks CLI flags. However, there are material gaps versus the description. Most importantly, the description says it covers both WAF generations across CLI/SDK/raw RPC, but the code explicitly states that public metadata only exists for 2019-09-10 and 2021-10-01 and exits with an error for other WAF 2.0 versions rather than diagnosing them. Also, the description promises to 'return a corrected call in the same channel,' but the implementation only prints specs/findings and does not construct a corrected SDK/CLI/raw RPC invocation. These are substantive description-behavior mismatches rather than minor implementation details.
- Content
