Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The manifest materially understates the skill's capabilities by claiming it only reads Outlook mail and drafts replies, while the body documents broader access to calendar events, contacts, bulk export of email bodies, and attachment indexing. This mismatch can mislead users and reviewers into granting browser/session access without understanding the full data exposure and operational scope.
