Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill exposes a generic proxy request capability that can reach arbitrary Bitbucket API endpoints, but the manifest/description does not clearly disclose that breadth. This can cause the skill to be invoked for seemingly routine Bitbucket tasks while actually enabling much broader read/write operations than users or orchestrators may expect.
