Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The skill description frames the tool as an operations/query assistant, but the code also includes create/delete endpoint actions that can change cluster exposure, including enabling extranet access. This mismatch can mislead users or higher-level agents into invoking mutating, security-impacting operations in a context where read-only behavior is expected.
