Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is branded as a narrowly scoped OpenAI TTS integration, but its setup text explicitly auto-configures access to hundreds of unrelated APIs, including scraping, social, and email capabilities. This scope expansion can cause an agent or user to trust and install a much broader third-party gateway than expected, increasing the chance of unintended tool use and data exposure.
