Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The example contract explicitly says to fetch the body of a public Google Doc, which conflicts with the stated skill boundary that it is manual-run only and does not fetch external documents automatically. This kind of scope contradiction is dangerous because implementers may follow the example rather than the manifest and add remote retrieval behavior, increasing exposure to untrusted external content, privacy issues, and accidental capability creep.
