Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest describes the skill as limited to 'searching and reading data,' but the documented actions include `render_document`, which performs active content generation and can consume quota or trigger downstream processing. This mismatch can cause an orchestrating agent or user to grant broader operational authority than intended, undermining informed consent and safety expectations.
