Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill advertises a scoped Kibana integration for saved objects, dashboards, data views, spaces, alerts, and fleet, but the documented API surface also exposes connectors/actions, security role inspection, and cases endpoints. This scope expansion increases the reachable privilege and data surface beyond user expectations and makes it easier for an agent to perform sensitive operations not clearly justified by the manifest.
