Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill metadata says it fetches Douyin account info and recent works, but the implementation also supports submitting upstream account ingestion/synchronization requests. This expands the tool's behavior beyond passive viewing into triggering remote data collection workflows, which is a capability mismatch and can cause users to initiate third-party processing they did not expect.
