Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The undocumented 'json' command allows callers to query arbitrary Spotify API endpoints, expanding the skill beyond its stated listening-history and recommendation purpose. In an agent setting, this broadens account data access and may expose profile, library, playlist, or other Spotify data that users would not reasonably expect from the manifest.
