Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest advertises the skill as being for managing organizations, but the body describes chatbot, knowledge-base, and generic proxy capabilities. This scope mismatch can cause the skill to be invoked in contexts the user did not intend, increasing the chance of unauthorized or surprising actions against unrelated KodaGPT resources.
