Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The documentation explicitly tells operators to trust a self-signed certificate for the internal endpoint without any warning about certificate pinning, fingerprint verification, or the man-in-the-middle risk. In practice, this can train users to bypass TLS validation and expose the MCP connection, including the Bearer API key and tool traffic, to interception or endpoint spoofing on internal networks.
