Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The manifest describes the skill as only for 'searching and reading data,' but the documented actions include `start_test`, which changes remote state by initiating a new GTmetrix test. This mismatch can mislead users or orchestrators into invoking the skill under a read-only assumption, resulting in unintended actions and resource consumption.
