Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is scoped as a Zip Archive API integration, but its documented connection flow explicitly allows creating connectors for arbitrary apps when no known app matches the supplied URL. That expands the skill from a narrow archive API integration into a general external-app connector, which can let an agent access unintended services and violate user expectations or least-privilege boundaries.
