Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is scoped as an API Sports integration, but these instructions allow the agent to create a new Membrane app/connector automatically when no known app matches the supplied URL. That expands behavior from a bounded sports-data integration into generic connector creation against arbitrary domains, increasing the risk of unintended external access and scope creep beyond what the manifest communicates.
