Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is presented as an AI21 Labs integration, but its documented proxy capability permits arbitrary direct API requests, including state-changing methods like POST, PUT, PATCH, and DELETE. That broadens the operational scope beyond narrowly defined actions and can enable unintended or overly powerful interactions if the agent is invoked under the assumption that it is limited to safe, predefined operations.
