Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest advertises broad capabilities like managing data, records, and workflows, but the documented implementation is mainly for document generation plus a generic API proxy. This mismatch can cause the skill to be invoked in contexts broader than intended, increasing the chance an agent uses powerful networked functionality without clear scope boundaries.
