Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use WebSearch when user-provided brand information is incomplete, which expands the skill's behavior from local user input processing into external data retrieval. This can introduce privacy, consent, and data provenance risks because the user may not expect their query to trigger outbound searches or incorporation of untrusted third-party content.
