Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The implemented CLI exposes destructive and permission-affecting capabilities such as delete, checkout/checkin, edit, and organization-wide edit-link creation, while the published skill description emphasizes 'secure SharePoint file operations' and document intelligence without clearly disclosing those actions. This mismatch can cause users or orchestrators to grant trust or invoke the skill under incomplete assumptions, increasing the risk of unintended destructive or sharing operations.
