Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest frames this as a unified social data API skill, but the file also introduces generic webhook hosting and arbitrary third-party event ingestion. That scope expansion is security-relevant because it grants the skill a broader data collection and integration surface than users would reasonably expect from the declared purpose.
