Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented primarily as a read-only MCP querying integration, but it also instructs use of a separate REST API that performs a POST to create scheduled reports. That expands capability from passive querying to state-changing external actions, which can surprise the agent/runtime and cause unreviewed outbound data transmission or persistent report creation.
