Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The file documents direct-message sending commands even though the skill metadata says this skill is specifically for DingTalk group chat. That scope expansion increases the agent's reachable actions from group operations to one-to-one messaging, creating a capability mismatch that could enable unintended outreach, privacy violations, or abuse if the agent follows the reference instead of the declared scope.
