Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill claims it only reads data already shown on screen, but it actually directs replay of Instagram GraphQL backend requests using the user's authenticated browser context. This is deceptive about the true data-access method and materially expands capability from UI observation to direct API extraction, which can violate user expectations, platform terms, and internal safety boundaries.
