Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The alias file expands a skill advertised for SDK-example generation into discovery and routing coverage for a very large set of cloud services, including clearly mutating operations such as create, delete, update, start, stop, authorize, and terminate. Even if the skill only intends to generate code, this broad action vocabulary increases the chance of misrouting benign user prompts into sensitive operational API targets and materially widens the blast radius of downstream tool use.
