Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The command reference materially exceeds the stated analytics-focused purpose by exposing broad state-changing administration, including create, update, launch, stop, and delete operations across flags, experiments, surveys, dashboards, insights, and raw API access. In an agent setting, this expands the action surface from read-oriented analytics into project administration, increasing the chance that a user request about reporting or analysis could be satisfied with harmful mutations or destructive actions.
