Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The implementation checks OpenAI, OpenRouter, and Vercel, while the skill metadata claims support for Anthropic, OpenAI, OpenRouter, Mistral, and Groq. This discrepancy expands or shifts operational scope in a way users may not expect, undermining informed consent and making the skill behave differently than advertised. In a credential-handling tool, scope drift is security-relevant because it can trigger access to different accounts and secrets than the user intended.
