Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill’s stated purpose focuses on managing Smartcar data and workflows, but the documented capabilities include high-impact state-changing vehicle controls such as lock, unlock, start charge, and stop charge. This creates a scope mismatch that can cause an agent or user to invoke the skill for seemingly read-only tasks while unintentionally enabling physical-world actions against a vehicle.
