Description-Behavior Mismatch
Medium
- Confidence
- 85% confidence
- Finding
- The skill is branded and described as a New Relic integration, but its connection flow explicitly allows Membrane to create a new app/connector automatically when the URL does not match a known app. That expands the operational scope beyond the declared integration and could let an agent pivot into arbitrary connector creation or unintended third-party access paths if the input URL is influenced by user prompts or model error.
