Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The documentation explicitly states that the same key can be used on the broader thecolony.cc platform for posts, comments, and karma, which expands the effective privilege and scope of this DM-focused skill. That creates a scope-confusion risk: an operator may authorize this skill for messaging but inadvertently grant credentials usable for broader social actions elsewhere on the platform.
