Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest and metadata frame the skill as suitable for 'searching and reading data,' but the body explicitly discusses create, update, send, post, delete, and remove actions that can change TikTok Business state. This mismatch can mislead orchestrators or users into invoking the skill under a read-only assumption, increasing the risk of unintended state-changing operations.
