Description-Behavior Mismatch
High
- Confidence
- 96% confidence
- Finding
- The README describes a paper-downloading skill, but it also states that the agent will automatically run `git pull --ff-only` on first invocation and immediately apply updates. That is a material hidden capability change: executing code from a remote repository at runtime expands trust boundaries and can turn a benign fetcher into a remote code delivery mechanism if the repo is compromised or the upstream changes unexpectedly.
