Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest markets the skill as a shopping/payment tool, but the file also exposes seller monetization features such as payment links, invoices, storefronts, and public shops. This scope mismatch can mislead users and agents into granting trust and permissions under a narrower expectation than the skill actually requires, increasing the chance of unintended financial or data exposure.
