Description-Behavior Mismatch
Medium
- Confidence
- 86% confidence
- Finding
- The changelog states the skill supports 10 OCR document types, while the manifest describes it as specifically for Chinese mainland business licenses. This capability mismatch can mislead users and reviewers about the actual data the skill can process, expanding the effective attack surface to additional sensitive document classes such as IDs, bank cards, and invoices.
