Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The file explicitly broadens the skill from onboarding into general account operations after assistant creation. Even if useful operationally, bundling unrelated powers into one skill makes least-privilege enforcement harder and increases the blast radius of a mistaken invocation or prompt-injection-driven action. In this context, the skill can move from collecting setup details to managing live account assets without a clear trust boundary.
