Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill metadata says it creates an Instagram carousel, but the workflow later performs a materially different action: publishing to Instagram. This hidden scope expansion is dangerous because an agent or user may authorize content generation without realizing the skill also posts to an external account, creating unintended account-affecting side effects.
