Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest description says the skill manages Projects and Companies, but the body documents broader capabilities including tasks, mailboxes, conversations, workflows, and arbitrary proxied API requests. This mismatch can cause the agent or user to invoke the skill under incomplete assumptions, increasing the chance of unexpected high-impact operations being performed.
