Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The file documents a separate feedback API that is outside the skill’s stated bibliography-query purpose. Expanding a skill’s documented capabilities to include an additional outbound endpoint increases attack surface and creates a path for unintended external data transmission, especially if an agent automatically follows all documented APIs in a skill package.
