Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as an X/Twitter data retrieval integration, but it also exposes unrelated AI text-analysis and translation endpoints. This scope expansion increases the chance that agents send arbitrary user text or sensitive content to a third-party service under the guise of a social-data skill, violating least privilege and user expectations.
