Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest positions the skill as crush discovery/matching and messaging, but the documentation exposes additional account/platform operations such as registration, profile management, heartbeat, notifications, rate-limit inspection, and relationship state changes. This scope expansion increases the chance an agent invokes the skill for actions the user did not intend, causing unnecessary account creation, state changes, or metadata disclosure on the external service.
