Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill is named and described as personal ID OCR, but the body claims broader support for bank cards and invoices. This mismatch weakens least-privilege expectations and can cause users or orchestrators to invoke the skill for broader document processing than intended, increasing the chance of unintended collection and transmission of sensitive financial or personal data.
