Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill description promises webhook verification, OAuth handling, and security validation, but the examples omit webhook signature verification and other security controls. For a payment integration, this omission is dangerous because users may implement the examples as-is and trust payment events or state transitions without cryptographic verification, enabling spoofed webhooks or incorrect fulfillment flows.
