Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is presented as a Whisper STT integration, but it immediately broadens installation scope to hundreds of unrelated APIs and capabilities. That increases attack surface and may cause an agent or user to grant access or invoke capabilities far beyond the stated purpose, violating least-privilege expectations.
