Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as a wallet, payments, trading, email, and identity tool, but it also exposes a broad AI gateway and image generation capability that materially expands what the agent can do. This scope creep weakens least-privilege boundaries and can let callers use an ostensibly finance-focused skill for unrelated networked inference, prompt relay, and file creation actions that were not justified or clearly disclosed in the manifest purpose.
