Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is described as answering yoga pose questions, but the script retrieves up to 100 full records from a remote NocoDB table rather than narrowly fetching only the data needed for a specific user query. This creates unnecessary data exposure and violates least-privilege/data-minimization principles, especially because the table contents may include metadata or fields not intended for end users.
