Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill metadata and description present the capability as image generation, but the workflow explicitly authorizes `web_search` for cities, brands, and movie scenes. This creates a scope mismatch that can surprise users and reviewers, and may cause unintended outbound data access or policy bypass if user inputs are sent to external lookup tools without clear disclosure.
