Description-Behavior Mismatch
Low
- Confidence
- 84% confidence
- Finding
- The skill supports sending arbitrary user-provided content to an external validation endpoint, but this inspection behavior is not clearly disclosed in the manifest description. That mismatch can cause users or invoking systems to route sensitive content into a third-party API without informed consent, creating privacy and data-handling risk.
