Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 98% confidence
- Finding
The declared description says the skill is for security/risk preflight on x402 endpoints and Base addresses before purchases or wallet interactions. The supplied code does something materially different: it is a local sanity-check script for the skill repository itself. It reads SKILL.md and README.md, asserts the presence of certain metadata and strings, checks for required files, and ensures likely secrets are not present in docs. It explicitly states 'no hosted API requests' and contains no logic for evaluating x402 payment terms, Base recipients, blockchain data, endpoint safety, or user-authorized transactions. This is a clear description-behavior mismatch with a different primary purpose.
- Content
