Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The template grants `write` and `browser` capabilities to a client-facing consulting agent even though its stated role is answering domain questions in Feishu and consulting from a knowledge base. These extra capabilities materially expand the attack surface: prompt injection or social engineering could steer the agent into modifying local files, navigating arbitrary sites, or exfiltrating data through browser actions beyond the intended consulting workflow.
