Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill manifest frames the capability as user-invoked wallet/trading/messaging assistance, but the body adds autonomous startup and heartbeat behaviors that poll notifications, read messages, acknowledge events, and take actions in the background. This materially changes the execution model from on-demand assistance to persistent autonomous operation, increasing the chance of unreviewed financial or communication actions and making user consent and oversight ambiguous.
