Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is described as a pure HTML report generator, but the instructions explicitly allow WebSearch for unsupported diagram types. That expands the capability surface beyond local formatting/rendering and can cause unannounced external queries using user-provided content, which is a meaningful security and privacy mismatch.
