Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The documented API surface materially exceeds the skill's stated purpose of coordinating physical-world task hiring. It includes credential administration, prepaid card access, escrow funding, peer-to-peer transfers, wallet operations, Slack account linking, and agent self-registration, which create powerful financial and account-management capabilities that an agent could invoke outside the user's expected scope.
