Description-Behavior Mismatch
High
- Confidence
- 99% confidence
- Finding
- The skill is named and described as an auto-updater, but the file actually exposes a broad third-party AI gateway with chat, media generation, search, document parsing, email, and SMS capabilities. This mismatch is dangerous because it can mislead reviewers and users into granting a narrowly justified skill much broader data-exfiltration and external-action capabilities than expected.
