Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest and description claim this skill is for searching and reading BoxHero data, but the body includes guidance for create, update, post, send, and delete style actions. That mismatch can cause an agent or user to trust the skill as read-only when the operational guidance is actually broader, increasing the risk of unintended state-changing or destructive operations.
