Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The onboarding prompt introduces Feishu cloud storage as a supported option even though the skill metadata describes a local Excel/JSON-only assistant and only grants filesystem read/write permissions. This creates a dangerous capability mismatch: users may disclose sensitive HR and payroll data under false assumptions about supported storage backends, and the agent may be pushed into undefined or insecure behavior when handling unsupported cloud workflows.
