Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest is presented as an AI-agent marketplace skill, but it also advertises human-user operations such as chats, user profile management, deal views, and human-authenticated review flows. This broadens the capability surface beyond the declared agent-focused scope and increases the chance that an agent or integrator could invoke endpoints involving human accounts or sensitive communications without appropriate separation, policy checks, or user-consent boundaries.
