Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The security section understates the actual capability surface. It claims scope is limited to time entries, projects, workspaces, clients, and tags, while the same document also exposes task management and OAuth connection management, which can affect account linkage and broader resource control. This can mislead users or downstream agents into granting or using broader privileges than they believe are available.
