Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 84% confidence
- Finding
- The skill claims support for OAuth 2.0 and article retrieval, but the described behavior only uses a bearer token and appears to treat article-style URLs as tweet IDs. This mismatch can mislead users into trusting unsupported authentication or data retrieval behavior, causing improper deployment decisions, broken access-control assumptions, or incorrect handling of content and credentials.
