Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a Gmail REST API integration, but it explicitly instructs the agent to perform arbitrary web search and page fetching with other tools before composing email content. This broadens the skill's effective capability beyond the declared scope, increasing the chance of prompt-driven data exfiltration, unreviewed browsing, or unintended access to unrelated external sites.
