Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The manifest advertises a narrow purpose of deploying NFT collections, but the skill documentation exposes materially broader capabilities including agent registration/claim workflows, webhook configuration, and premium listing/analytics endpoints. This capability mismatch can mislead users and agent frameworks about the true network and data-handling surface, undermining informed consent and least-privilege review.
