Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The README for an Excel-focused skill advertises unrelated capabilities such as workflow execution, database operations, chart generation, and Feishu Sheets integration. In an agent skill context, this can mislead orchestration or users into invoking broader functionality than declared, increasing the attack surface and creating opportunities for unauthorized data access or unintended tool routing.
