Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The templates embed branding and operational instructions for a different tool ('flyai'/'flyai-cli') than the declared Fliggy-powered luxury-hotel skill. This can mislead users into invoking the wrong CLI, trusting an unrelated service, or disclosing travel queries and booking-related data to an unintended system, creating a supply-chain and phishing-style confusion risk.
