Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented as a product-query skill, but the documentation also advertises `/mcp/create_activity`, which is a state-changing remote action. This scope expansion is dangerous because agents or users may invoke modification capabilities without realizing the skill can create remote records, increasing the chance of unintended actions on an external service.
