Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill description promises access to dashboards, data sources, folders, annotations, alerts, and teams, but the documented API surface also includes service account enumeration and plugin listing. Expanding the effective capability beyond the declared scope weakens user consent and least-privilege assumptions, because an agent could access administrative inventory data the user may not expect.
