Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill claims to wrap only GET /image/motou, but its manifest also advertises unrelated capabilities like image compression, image/base64 conversion, and other image tasks. This can cause the orchestrator to route requests for broader image operations into a skill that is not scoped for them, increasing the chance of unintended API calls, misuse, or user-task confusion.
