Description-Behavior Mismatch
Medium
- Confidence
- 86% confidence
- Finding
- The skill advertises replying in the current channel but also authorises autonomous cron-driven outbound messages later. That creates a behavioural mismatch where the skill can send unsolicited status and alert messages after the initiating interaction, increasing the risk of notification abuse, accidental disclosure into a shared channel, or user surprise if the scheduling context is misunderstood.
