Description-Behavior Mismatch
High
- Confidence
- 99% confidence
- Finding
- The script performs document collection from a banking document archive using a direct API, which exceeds the declared skill scope of login/logout, account listing, and transaction retrieval. In a banking context, this scope expansion materially increases access to sensitive financial records and bypasses the user's reasonable expectations about what the skill will do.
