Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill metadata says it manages contacts, companies, products, tags, documents, brands, automations, team members, and organization data, and this file explicitly documents organization and team-member administration APIs including user invitation, user editing, department creation, and branch creation. In an agent skill, exposing broader administrative capabilities materially increases the chance that a user request or prompt injection could lead to account provisioning or org-structure changes beyond what a narrowly scoped data-management integration would need.
