Description-Behavior Mismatch
High
- Confidence
- 96% confidence
- Finding
- The manifest says the skill is for 'searching and reading data,' but the documented actions include `call_service` and `fire_event`, which can modify Home Assistant state. This mismatch can cause downstream agents or users to trust the skill as read-only and invoke it in contexts where state-changing operations should require stricter consent and review.
