Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- This ABI for a user-facing NFT trading skill exposes owner and upgrade-style administrative methods such as extend, registerMethods, rollback, migrate, transferOwnership, and owner. Even though an ABI alone does not execute anything, including these capabilities in a skill materially broadens what an agent could be induced to call, enabling proxy reconfiguration, ownership changes, or migration operations that are far outside the declared trading purpose.
