Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented as a payout tool, but the documentation also exposes team metadata access and full webhook management. This scope expansion increases the blast radius beyond the stated purpose, enabling persistence, outbound notification changes, or account reconnaissance if an agent is granted the skill without understanding the extra capabilities.
