Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is marketed as embeddings-focused, but it also documents general chat completion, image generation, speech-to-text, model pulling, and monitoring endpoints. This scope expansion increases the attack surface and may cause an agent or user to invoke capabilities that exceed the stated purpose, violating least-privilege expectations.
