Tp4
High
- Category
- MCP Tool Poisoning
- Confidence
- 86% confidence
- Finding
- The documented behavior says the plugin is for an OpenAI-compatible model endpoint, but the analyzed behavior also includes image generation, task polling, and downloading generated assets from returned URLs. That mismatch is dangerous because users and reviewers may approve the plugin expecting only standard model inference traffic, while the plugin can make additional network requests and retrieve remote content, expanding the trust boundary and attack surface.
