Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
- The documented behavior goes beyond simple bulletin querying and includes credential persistence, token inspection, and local credential sourcing, none of which are disclosed in the top-level purpose. This is dangerous because users may provide sensitive tokens without understanding they are stored persistently on disk and partially exposed through status commands, creating confidentiality and consent risks.
