Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The manifest and description frame the skill as suitable for 'searching and reading data,' but the documented action performs content generation and uploads the result to connector transit storage. This mismatch can mislead an agent or reviewer into treating the skill as read-only, reducing scrutiny and increasing the chance that a state-changing or cost-incurring action is run without proper user confirmation.
