Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The manifest says the skill is for managing Organizations, Users, and Goals, but the body of the skill enables arbitrary action discovery and raw proxy access to the Scale AI API. This mismatch can cause the agent or user to underestimate the skill's actual authority, increasing the chance of overbroad use, unintended data access, or execution of sensitive operations outside the declared scope.
