Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill file adds a separate cross-border experience query capability, including customer-specific full-process fulfillment metrics, that is not described in the manifest. This creates hidden functionality and weakens trust boundaries: users and reviewers may authorize a logistics-indicator skill expecting one scope while the skill can access additional customer-level data paths.
