Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The documented connection flow is broader than the skill’s declared Pylon-specific purpose because it allows creating a new app/connector automatically when no known app is found. That can expand the skill from a scoped SaaS integration into a generic external-service integration path, increasing the risk of unintended data access or actions against non-Pylon targets.
