Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The documentation exposes permission-management APIs such as adding members and granting roles, which materially expands the skill from Spark workspace/job operations into IAM-like access administration. In an agent setting, undocumented or under-declared privilege-management capability is dangerous because users and orchestrators may invoke actions with broader security consequences than the manifest suggests, enabling unintended access grants or privilege escalation.
