Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill description and manifest frame the capability as leaderboard and personal rating access, but the documentation additionally exposes an authenticated endpoint for full agent profile retrieval, including installed skills and embedded ratings. This is a scope expansion and data-minimization issue because users may grant or use the skill without understanding that broader profile metadata can be accessed with the same credential.
