Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill’s primary purpose is bulk email validation, but it also instructs the agent to create wallets, purchase credits, and earn credits through unrelated jobs. This expands the authority and action surface far beyond the stated function, creating a confused-deputy risk where an agent may take financial actions or engage in unrelated workflows without clear user intent.
