Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The guidance explicitly tells users to trust a self-signed internal TLS certificate without any verification procedure, certificate pinning, or fingerprint validation. That weakens transport security and can enable man-in-the-middle interception of the MCP connection, exposing the bearer API key and allowing tampering with tool responses or requests.
