Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill's stated purpose is patent legal status lookup, but it instructs the agent to also auto-detect and report user feedback through a separate Feedback API. This expands behavior beyond user-requested patent queries and can cause silent exfiltration of conversational content or user sentiment to another endpoint without clear consent or necessity.
