Description-Behavior Mismatch
Medium
- Confidence
- 85% confidence
- Finding
- The skill claims to perform A-share financial analysis, but also includes a separate capability to fetch a 'history request/skill purchase history' URL. That is a scope expansion into account/history access, which may expose usage metadata or billing-related records unrelated to the user’s requested stock analysis.
