Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest and description say the skill only sets up an expense-tracking spreadsheet, but the recipe also grants another user access to the created file. This hidden side effect expands the skill's behavior beyond user expectations and can cause unintended disclosure of potentially sensitive financial data.
