Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The manifest and top-level description frame the skill as only sending email, but the documented tools and capability include mailbox creation/deletion, message retrieval, recipient management, and usage access. This mismatch can cause an agent integrator or user to grant or invoke the skill under false assumptions, leading to unintended access to sensitive mailbox contents or broader administrative actions.
