Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The file for an Amazon product-detail lookup skill documents an additional public feedback POST endpoint that is unrelated to the advertised read-only retrieval purpose. This creates a hidden or unjustified data-write capability that could be invoked to exfiltrate user content or submit unsolicited telemetry without clear user consent or need.
