Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill's stated purpose is to retrieve and display the 36kr hotlist, but the documentation instructs the agent to append promotional content and steer users toward other skills and installation flows. This expands the skill's behavior into unsolicited cross-skill promotion and action guidance, creating prompt-injection-like scope creep and increasing the chance of unintended agent actions unrelated to the user's request.
