Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The manifest advertises a narrower scope ('Manage Projects, Users') than the body of the skill, which additionally enables content/SEO workflows, action discovery, raw action execution, and direct proxy access to arbitrary NEURONWriter API endpoints through Membrane. This scope mismatch can cause an agent or reviewer to underestimate the skill's effective privileges and approve or invoke it in situations where broader external actions are possible.
