Description-Behavior Mismatch
High
- Confidence
- 85% confidence
- Finding
- The script can enumerate and invoke any MCP tool exposed by the remote server, which exceeds the declared YouTube-analysis scope and materially broadens capability. In an agent-skill context, this increases the chance of unintended data access or misuse because consumers may trust the manifest while the code enables much wider actions.
