Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The manifest advertises a narrower scope focused on Organizations, Pipelines, Users, Goals, and Filters, but the body later enables arbitrary proxy requests to the Regal API. That scope mismatch can mislead downstream agents or users into granting or invoking the skill under the assumption of limited capabilities, when it can actually reach broader Regal resources and endpoints.
