Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 81% confidence
- Finding
- The documented behavior does not fully match the implemented behavior: undisclosed support for non-driving modes, forcing a Google Maps link to driving mode, and an undisclosed es-419 languageCode can mislead users and downstream agents about what data is being requested and returned. In a routing skill, this can cause incorrect transportation guidance, user confusion, and privacy/compliance issues because location data is sent under conditions the user was not clearly told about.
