Description-Behavior Mismatch
Medium
- Confidence
- 84% confidence
- Finding
- The manifest advertises a narrow purpose (setup/start mining), but the document instructs the agent to perform additional sensitive actions including key export, funding/bridging, wallet distribution, and wallet-file discovery. Capability mismatch matters because operators may approve the skill expecting limited behavior while the skill can access or influence funds and secrets far beyond that scope.
