Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest metadata conflicts with the provided skill identity and purpose: the user-facing context says 'stripe-wallet' while the manifest names 'creditclaw-stripe' and describes broader shopping and approval workflows. This kind of branding and scope mismatch can mislead users about what service they are authorizing and what capabilities the skill may exercise, increasing phishing, trust-confusion, and over-permission risk.
