Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The documented design principles explicitly allow binding arbitrary tools and custom extensions, which materially broadens the skill from a financial-product workflow into a general integration/orchestration surface. In an agent setting, this scope creep increases the chance the skill can be repurposed for unrelated or unsafe actions that users did not expect from the declared skill purpose.
