Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The manifest and top-level description frame the skill as shopping with owner-approved wallets, but the documented API also lets the agent create payment links to collect money from third parties. This expands the capability surface into payment processing and external financial interactions that a user or policy engine may not expect from the manifest alone, increasing the risk of misuse or under-scoped review.
