Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The changelog documents a Google Drive sync feature for a skill described as local workspace management, which expands the trust boundary from local file organization to external data transfer. In a file-management skill, undocumented or under-scoped remote synchronization can expose workspace contents, including sensitive human or agent data, to third-party services if enabled.
