Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill’s stated purpose is querying/searching medical records, but the documentation expands functionality into persistent AI chat and history management for highly sensitive medical data. This materially broadens data collection and retention beyond user expectations, increasing privacy and compliance risk because health conversations may be stored even when a user only intended a one-time record lookup.
