Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The setup document provisions a general-purpose Octagon MCP instance exposing tools for broad market intelligence, web scraping, and deep research, which exceeds the stated commodity-quote skill scope. This violates least privilege: a user enabling this skill may unknowingly grant an agent access to much broader data retrieval and external interaction capabilities than expected.
