Description-Behavior Mismatch
High
- Confidence
- 95% confidence
- Finding
- The manifest and top-level description say the skill manages CRM-style entities like Persons, Organizations, Deals, Leads, Projects, and Activities, but the body of the skill is for Reward Sciences reward-program APIs. This mismatch can cause an agent to invoke the skill in the wrong context and then send queries or mutating requests to an unrelated external system, creating a real risk of unintended data access or modification.
