Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill description frames the capability as owner-approved shopping, but the documented payment-link feature allows the agent to charge arbitrary third parties. That materially expands the financial behavior and trust boundary of the skill beyond the manifest, which can mislead operators and enable unexpected monetization or fraud workflows.
