Description-Behavior Mismatch
Medium
- Confidence
- 89% confidence
- Finding
- The manifest explicitly says the skill should not trigger for deployment or serving requests, yet the documented visualization workflow starts a long-running web service and recommends binding it to 0.0.0.0. That creates a capability/behavior mismatch that can cause the agent to assist with exposing a service on the network when users did not ask for serving functionality.
