Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest and top-level description frame the skill as managing workspaces, users, and roles, but the documentation also exposes a generic proxy mechanism for arbitrary Baserow API requests. This broadens the effective capability of the skill beyond what a caller may reasonably expect, increasing the chance that an agent uses powerful direct API access without appropriate scrutiny or user confirmation.
