Description-Behavior Mismatch
Medium
- Confidence
- 87% confidence
- Finding
- The skill’s declared purpose is multi-airport airfare comparison, but it instructs the agent to also fetch hotel and attraction booking links. That broadens tool usage and user redirection beyond the stated scope, increasing the chance of unnecessary data access, affiliate-style steering, or actions the user did not request. In a travel context this is not inherently malicious, but it is a real scope-expansion risk.
