Description-Behavior Mismatch
High
- Confidence
- 97% confidence
- Finding
- The skill is marketed as OCR-specific, but the setup text grants broad access to hundreds of unrelated APIs including scraping, social data, and email. This scope mismatch can cause an agent or user to install a far more capable integration than intended, violating least privilege and increasing the chance of unexpected data access or exfiltration through unrelated capabilities.
