Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is presented as read-only, but it explicitly recommends that users may supply a full-access Stripe secret key. If the agent, surrounding platform, or future skill changes issue non-read requests, that key could enable refunds, subscription changes, or other destructive account actions far beyond the skill's stated scope.
