Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is declared as a DocuGenerate integration, but the documented `membrane connection ensure` flow explicitly allows creating connectors for arbitrary apps or domains if no known app is found. That expands the effective trust boundary far beyond the stated scope and could let an agent be steered into interacting with unintended third-party services under this skill.
