Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill’s declared purpose is ad-creative generation, but this section extends into pulling performance data, managing campaigns, and upload workflows via external tools. That scope expansion increases the chance an agent with broader tool access performs account-affecting actions beyond the user’s likely intent, especially if the skill is auto-invoked or interpreted as authorization to operate ad platforms.
