Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The manifest description materially understates the skill's capabilities. It advertises posting, replying, searching, liking, retweeting, and analytics, but the body also supports delete, follow/unfollow, bookmarks, list management, and media upload, which can change a user's account state and access local files. This weakens informed consent and can cause an agent or user to approve broader-risk behavior than the metadata suggests.
