Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- This Sankey-specific skill ships a general-purpose CLI that can authenticate, inspect quota, create unrelated chart/PPT/3D projects, and download exports, which materially exceeds the declared scope of 'Sankey diagram generation'. In an agent setting, unnecessary capabilities expand the attack surface and enable unintended data exfiltration or misuse if the agent is prompted or compromised to invoke broader commands.
