Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The manifest and description frame the skill as limited to searching and reading data, but the documented actions include workflow execution operations such as run_workflow and run_saved_workflow. That mismatch can mislead an agent or reviewer into treating the skill as read-only, increasing the chance that active operations are invoked without appropriate caution or user confirmation.
