Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
The declared purpose says the skill filters spam, but the documented behavior also includes reading API credentials, making authenticated API calls, scanning feeds, and displaying feed content. That mismatch broadens the effective trust boundary and can mislead users into approving a tool with more access and functionality than its summary implies.
- Content
