Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest advertises a narrower scope of managing users and organizations, but the body documents materially broader capabilities including lessons, subscriptions, invitations, and arbitrary proxy access to the Linguapop API. This scope mismatch can mislead routing, approval, and user-consent decisions, causing the agent to invoke a skill with more authority than expected.
