Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a payment helper, but it also exposes sensitive administrative and data-governance capabilities such as token creation/revocation, agent provisioning, GDPR export/delete, and system configuration. This mismatch increases the chance an agent or integrator grants the skill broader authority than intended, enabling destructive or privacy-impacting actions under the guise of routine checkout functionality.
