Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest and description tell users this skill is for 'searching and reading data,' but the body explicitly states that write and destructive actions may exist and can be run through the same skill. This creates a trust-boundary mismatch: callers, reviewers, or policy engines may classify the skill as read-only while it can actually perform state-changing operations if such actions are exposed by the connector.
