Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is described as a personal read-only company-info query tool, but its documented workflow directly calls a /collect endpoint and supports force_refresh behavior that can trigger active server-side collection. This is a capability mismatch that can mislead users and operators about what actions the skill performs, increasing the risk of unintended external requests and data gathering.
