Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- This file exposes a generic model-enumeration capability by calling /v1/chat/models and returning the full filtered model list, which goes beyond the stated ad-copy-writer purpose of generating marketing text. In an agent setting, this kind of scope expansion can aid capability discovery, provider fingerprinting, and unauthorized workflow composition, especially if downstream policy relies on the skill manifest to constrain behavior.
