Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill declares that transfer execution depends on MCP tools, but the required preregistration step uses an additional `antalpha-register` tool that is not listed in the runtime capability section or manifest requirements. This mismatch can cause agents to operate with incomplete capability assumptions, leading to authentication failures, unexpected fallback behavior, or insecure substitution of registration/credential handling outside the declared tool boundary.
