Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The manifest markets the skill as a narrow 'proactive agent' capability, but the content exposes a broad multi-service API wrapper including search, scraping, document parsing, email, and SMS. This mismatch can mislead users and downstream policy systems about the real capability surface, increasing the chance of unintended sensitive actions being enabled or approved.
