Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The skill states it is not for direct QBO OAuth setup, yet it includes code that performs a refresh-token exchange using client credentials and a refresh token. This inconsistency can mislead users about the skill's security boundary and encourages handling highly sensitive auth material inside the skill, increasing the chance of credential misuse or unintended token generation.
