Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill is described as an image recognition/mask-generation capability, but the referenced guide instructs across unrelated video, image synthesis, and audio generation APIs. This scope mismatch can cause an agent to invoke capabilities outside the declared purpose, increasing the attack surface and enabling prompt or workflow abuse through unintended tool usage. In this context, the issue is more dangerous because broad multimodal generation guidance is embedded in a narrowly scoped skill, which may confuse downstream routing and policy enforcement.
