Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 91% confidence
- Finding
- The declared description emphasizes an Amap-based city mystery experience, but the actual behavior includes weather queries, backend interactions for question management and answer verification, and creation of check-in/location URLs through an external service. This hidden expansion of data flows and third-party processing can mislead users and reviewers about what data is collected, where it is sent, and which external systems participate in the experience.
