Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill metadata frames Phos as a generic data/records/workflow tool, while the body describes a cloud-cost-management SaaS and then grants broad API access patterns through Membrane. This mismatch can cause the agent to invoke the skill in contexts broader than intended and perform sensitive operations against an infrastructure-finance system without clear user understanding.
