Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest and description frame the skill as limited to common home-control functions, but the documentation also allows calling any Home Assistant service. This creates a scope gap that can expose far broader actions than users or policy systems expect, including unlocking doors, opening covers, triggering automations, or invoking integrations with sensitive side effects.
