Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest description materially understates the skill's capabilities. While it claims to manage products, orders, messages, and settings, the file also exposes finance data, wallet receiving addresses, discount and collection management, profile updates, notifications, and public marketplace search. This mismatch can cause downstream reviewers, policy engines, or users to grant access under an incomplete understanding of what the skill can do.
