Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The documented connection flow is not constrained to Realm and explicitly allows finding or creating connections for arbitrary apps based on a URL or domain. That materially broadens the skill’s effective capability beyond its stated purpose, increasing the risk that an agent invokes it to access or configure unrelated third-party services under overly generic user requests.
