Description-Behavior Mismatch
Medium
- Confidence
- 85% confidence
- Finding
- The skill's body expands behavior beyond phone receipt management by directing the agent to send Telegram summaries for non-call cases, while the manifest advertises only phone receipt functionality. This scope drift can cause the agent to invoke an undeclared external delivery channel and transmit task information to a service the user did not explicitly authorize in the skill description.
