Description-Behavior Mismatch
High
- Confidence
- 97% confidence
- Finding
- The manifest description says the skill is for YouTube data, search, and trends, but the documented tool set also includes endpoints to retrieve channel email addresses. That materially expands the skill’s capability into personal/contact data collection, which can mislead users, reviewers, and policy systems about what the skill can do. The mismatch is especially risky because email extraction is a higher-sensitivity function than ordinary video metadata retrieval.
