Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill exposes ACL/share-management operations (`googlecalendar_acl_insert`, `googlecalendar_acl_delete`) that go beyond the manifest’s stated scope of scheduling and updating meetings. This creates an authority mismatch: a user or downstream agent selecting the skill for routine scheduling could unintentionally gain access to calendar-sharing capabilities that can expose calendar contents to third parties or alter access controls.
