Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill markets itself as a read-only Telegram history tool, but it also exposes billing and referral/account-management endpoints that are unrelated to the stated core purpose. This creates a scope mismatch that can mislead users and agents into granting trust or auto-invocation privileges to a skill that can trigger commercial account actions beyond message retrieval.
