Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest advertises the skill as limited to searching and reading data, but the documented actions include `run_actor`, which can trigger arbitrary Apify actor execution and real side effects. This mismatch can cause an upstream agent or user to trust the skill as read-only and invoke it in contexts where write/execute capabilities should have been disallowed.
