Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The manifest presents the skill as limited sales outreach to existing contacts, but the body grants a much broader autonomous email capability including account registration, receiving verification codes, reservations, and general correspondence. This mismatch can cause users or orchestrators to invoke the skill under false assumptions, enabling unreviewed external communication and credential-adjacent workflows beyond the declared scope.
