Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The OpenAPI spec exposes a credential-minting endpoint (/users/_token/) that accepts username and password and returns a user token, expanding the skill from catalog lookup and guarded collection writes into full authentication handling. In an agent setting, this materially increases risk because the skill could solicit or process raw user credentials and then access broad account-management endpoints with the minted token, which is far beyond the narrowly described scope.
