Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The manifest/skill description says purchases create real Stripe charges, but it omits several billing-management capabilities present in the API, including purchasing credits, enabling auto top-up, changing plans, and canceling subscriptions. This matters because an agent or user may not realize the skill can trigger ongoing or additional financial commitments beyond a one-time subscription purchase, reducing informed consent around monetary actions.
