Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The documented MCP surface includes account signup/login plus a broad freeform action channel that extends beyond the skill’s advertised vacation-rental turnover and cleaning scope. This creates a scope-expansion risk where an agent or user may invoke sensitive account actions or unrelated property-management operations without clear least-privilege boundaries.
