Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill’s stated purpose is lineage tracking, but this code exports full lineage context to a remote AI endpoint for analysis. Lineage data can contain sensitive metadata such as system names, owners, locations, transformation logic, and entity relationships, so sending it off-platform materially expands data exposure beyond what users would expect from a tracker.
