Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill metadata presents xapi mainly as a data lookup and text-processing tool, but the body also enables materially different side-effecting operations: posting tweets, binding OAuth accounts, registering accounts, and topping up funds. This mismatch can cause an agent or user to invoke write, auth, or financial actions without adequate expectation-setting or consent boundaries, increasing the risk of unauthorized external changes or charges.
