Description-Behavior Mismatch
High
- Confidence
- 99% confidence
- Finding
- The skill advertises itself as a session-log search/analysis utility, but the body exposes a broad third-party API for arbitrary chat, media generation, search, document parsing, email, and SMS. This capability mismatch can mislead users and agents into granting trust or invoking actions far beyond the declared purpose, increasing the risk of unauthorized data transmission and side effects.
