Description-Behavior Mismatch
Medium
- Confidence
- 87% confidence
- Finding
- The manifest markets the skill as generally managing 'data, records, and workflows,' but the actual capability set is document transformation plus a generic authenticated proxy to Api2pdf. That mismatch can cause an orchestrating agent or user to invoke the skill in broader situations than intended, increasing the chance that sensitive URLs, HTML, or files are sent to a third-party conversion service without clear user understanding.
