Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill describes the CLI as read-only while also saying it can 'manage custom and lookalike audiences,' which implies operations beyond passive data retrieval. This mismatch can cause the agent or user to authorize the skill under a false safety assumption, increasing the risk of unintended state-changing actions against an ad account.
