Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The documented minimum required policy adds `ces:metric:get`, expanding the skill's access beyond the stated OBS bucket listing/upload/scheduling scope. This violates least privilege and can expose unrelated monitoring metadata, increasing account reconnaissance capability if the skill or its credentials are misused.
