Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The file explicitly labels the skill as providing 'Safe read-only operations' while also documenting state-changing behaviors such as fund transfers and registration/referral flows. This mismatch can mislead an agent or operator into invoking the skill under the assumption that it cannot modify account state, increasing the chance of unauthorized or unintended actions.
