Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill is presented as a guidance assistant, but it embeds actionable browser-automation logic that navigates government sites, fills identity/travel forms, submits them, and stores confirmations. That meaningfully expands capability from advice to transaction execution on sensitive systems, creating risk of unauthorized submission, mishandling of personal data, and policy bypass if an agent operationalizes the pseudocode.
