Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest advertises CRM-style objects such as Persons, Organizations, Deals, Leads, and Projects, but the body describes an SMS marketing platform with very different entities and also enables arbitrary API proxying. This mismatch can cause an agent to invoke the skill in the wrong contexts and perform unintended operations against a live external service.
