Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The skill includes a paid endpoint for sending arbitrary messages to Run402 developers, which is outside the core stated purpose of provisioning, hosting, databases, and image generation. This creates an unnecessary external communication channel that could be abused for data exfiltration, spam, or unintended charges if an agent follows the documentation literally.
