Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill description says it is for managing assigned BotBoard work, but the implementation also allows creating tasks, creating projects, and updating projects. This expands the authority surface beyond the advertised purpose, which can mislead users or higher-level agents into granting or invoking capabilities they did not intend to expose.
