Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest presents this as a shopping/payment method skill, but the documented API also enables the agent to generate payment links and collect money from arbitrary third parties. That materially expands the trust boundary from 'spend under owner guardrails' to 'operate as a merchant/collector,' which can be abused for fraud, unauthorized billing, or social-engineering workflows not implied by the stated purpose.
