Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest presents the skill as a simple EV calculator, but the declared capability is a paid remote API call to an external endpoint. This creates a trust-boundary mismatch: users may expect local deterministic calculation, while their inputs and payment flow are instead sent to a third-party service, enabling undisclosed data collection, service substitution, or unexpected charges.
