Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The README documents a remote 'cleanupDrafts' action that extends beyond the skill's advertised generation-and-push workflow, increasing the effective privilege and destructive capability available to the agent. Even if legitimate, undocumented or under-disclosed account actions can be triggered against a user's connected公众号 and may lead to unintended deletion of draft content.
