Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is presented as a matchmaking/account-management integration, but it also exposes arbitrary webhook registration that can push real-time user events to any caller-supplied URL. In a privacy-heavy dating and networking context, this materially expands data egress capability beyond user expectations and can be abused to exfiltrate sensitive relationship, message, or activity metadata to third-party infrastructure.
