Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The README presents a file-search skill but also advertises a separate HTTP/SOAP media-server query interface, which expands the skill’s capability surface beyond the stated purpose. Undocumented or weakly justified secondary interfaces increase attack surface and make it easier to access or expose search-result data in ways users may not expect from a local file-search tool.
