Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The skill is described as a market-data query capability, but the OpenAPI spec also exposes a POST /contact endpoint that can send arbitrary user-supplied content to an external party. This is an unnecessary side-effecting capability outside the declared scope, increasing the risk of unintended data exfiltration or misuse if the agent invokes it based on conversational context.
