Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill is marketed as a data/monitoring/backtesting tool, yet it exposes process execution, pipeline creation, job scheduling, plugin/webhook triggering, and operational controls. In this context, the extra orchestration surface materially increases risk because an agent given a finance token may be able to alter workflows or trigger backend jobs beyond the user's expected intent.
