Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The documented behavior expands from a chat copilot/UI handoff skill into direct agent-side API execution against backend services, including parsing resumes and generating content from uploaded data. This materially changes the trust and data-flow model: instead of assisting in chat, the skill can autonomously send sensitive user resume and job data to remote services, increasing privacy and supply-chain risk.
