Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest description materially understates the skill’s actual scope, mentioning only a few IMDb capabilities while the OpenAPI spec exposes many additional operations such as search, news, reviews, rankings, and contribution-related endpoints. This can mislead users and reviewers about what data the skill can access and transmit, weakening informed consent and trust boundaries even though it is not direct code execution.
