Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest advertises the skill as only for 'searching and reading data,' but the documented actions include `launch_workflow`, which can change Seqera state. This mismatch can mislead an agent or user into invoking a write-capable skill under the assumption that it is read-only, increasing the risk of unintended workflow launches.
