Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest narrows the skill purpose to campaigns, leads, activities, schedules, and unsubscribes, but the documented API also exposes broader team/account and company data. This mismatch can cause users or orchestrators to invoke the skill under a false assumption of limited scope, increasing the chance of unintended access to more sensitive business information.
