Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The manifest claims the skill is for 'searching and reading data,' but the body of the skill discusses handling arbitrary Tally actions, including create/update/delete-style operations. This mismatch can mislead downstream agents or reviewers into granting broader trust than intended, increasing the chance that state-changing operations are invoked without appropriate scrutiny.
