Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly documents a generic proxy mechanism that can send requests to arbitrary IdealPostcodes API paths, which broadens the effective capability well beyond the declared postcode-management scope. This increases the chance an agent will perform unexpected external operations or transmit user data to endpoints the user did not intend, reducing least-privilege and transparency.
