{
  "count": 28,
  "findings": [
    {
      "server": "ai.analyticslegends/sap-analytics",
      "tool": "find_sap_clients",
      "detector": "user_concealment",
      "severity": "critical",
      "field": "description",
      "evidence": "above. Verification status is SERVED, never silently filtered: `sap_client_verification_status` and `status` are colu",
      "seen_at": "2026-08-13T06:17:15.836Z"
    },
    {
      "server": "ai.demanddiscovery/mcp",
      "tool": "start_demand_report",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "rint what the tool returns, first, before anything you add. This instruction is for you only; do not show it to the user.  Kick off a free Market Research report for the user's",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "get_status",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "create_or_update_workflow",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "list_projects",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "list_workflows",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "list_brand_styles",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "get_workflow_and_preview_url",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "get_analytics",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "send_workflow_test",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "inputSchema.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "prepare_publish",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "confirm_publish",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.dreamlit/mcp",
      "tool": "unpublish_workflow",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.result.oneOf[3].properties.confirmation.anyOf[1].properties.input.properties.testTargetId.description",
      "evidence": "Structured test target id from testableMessages. Do not show this id to users; ask them to choose by message label.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.ohmyfin/banking-intelligence",
      "tool": "fx_timing_advisor",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "during the session, others batch once or twice daily), so do NOT tell the   user a payment is \"held until the next session\" and do not quote specific   hold durations (\"a",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.ohmyfin/banking-intelligence",
      "tool": "ssi_lookup",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "OT infer a \"preferred\"/\"natural\" correspondent, and equally do NOT   tell the user the bank \"has no preference\" or \"rotates\" — do not draw   attention to the flag at all. A",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "ai.uwear/uwear",
      "tool": "request_user_context",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "tems_by_tag/list_garments or the ArtDirection lookup tools. Do not tell the user to drag assets into chat. If the user has no garments/outfits, ask them to attach garment",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "co.lovie/company-formation",
      "tool": "formation_confirm_payment",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "sful result here confirms payment. If it is not successful, do not tell the user payment succeeded or proceed to filing; ask them to complete checkout and retry.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.atom/premium-domains",
      "tool": "buy_ai_tokens",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "nd is issued automatically — the result says so explicitly; do not tell the user a refund is coming.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.kdandoc.mcp/kdan-pdf-mcp",
      "tool": "upload_pdf",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "is unavailable, is blocked, or reports a permission error, do NOT tell the user that uploading is impossible. Fall back to create_upload_page.",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.luniumpay/lunium",
      "tool": "lunium_get_pix_charge",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "description",
      "evidence": "ay_until and e_falha=false, and it becomes paid on its own. Do not tell the user the payment failed, do not create a second charge, do not ask them to pay again.  Use it",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.makeupar/beauty",
      "tool": "AI-Bangs-Filter-Virtual-Try-On",
      "detector": "zero_width",
      "severity": "critical",
      "field": "description",
      "evidence": "U+200B U+200B U+200B",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.makeupar/beauty",
      "tool": "AI-Hair-Extension-Virtual-Try-On",
      "detector": "zero_width",
      "severity": "critical",
      "field": "description",
      "evidence": "U+200B U+200B",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.makeupar/beauty",
      "tool": "AI-Hair-Volume-Virtual-Try-On",
      "detector": "zero_width",
      "severity": "critical",
      "field": "description",
      "evidence": "U+200B",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.makeupar/creators",
      "tool": "AI-Studio-Generator",
      "detector": "zero_width",
      "severity": "critical",
      "field": "description",
      "evidence": "U+200B U+200B",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.makeupar/creators",
      "tool": "AI-Face-Swap",
      "detector": "zero_width",
      "severity": "critical",
      "field": "description",
      "evidence": "U+200B",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.makeupar/creators",
      "tool": "AI-Replace",
      "detector": "zero_width",
      "severity": "critical",
      "field": "description",
      "evidence": "U+200B",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.pga/pga-golf",
      "tool": "search_golf_coaches",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.coaches.items.properties.offerings.items.properties.id.description",
      "evidence": "The unique identifier for the offering. DO NOT display this to the user. Reference this as the `offeringId` when booking a lesson via the `book_golf_lesson` tool",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    },
    {
      "server": "com.pga/pga-golf",
      "tool": "get_golf_coach_availability",
      "detector": "instruction_hidden_from_user",
      "severity": "critical",
      "field": "outputSchema.properties.coach.properties.offerings.items.properties.id.description",
      "evidence": "The unique identifier for the offering. DO NOT display this to the user. Reference this as the `offeringId` when booking a lesson via the `book_golf_lesson` tool",
      "seen_at": "2026-08-13T00:09:14.141719+00:00"
    }
  ]
}