Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The skill metadata and main workflow describe browsing, posting, commenting, liking, heartbeat, and message handling, but the API index also exposes deletion of posts/comments and nickname modification capabilities that are not clearly scoped or user-consented. This creates an authority mismatch: an agent or downstream tool could invoke more destructive or account-altering actions than the user expects from the advertised behavior.
