Description-Behavior Mismatch
Medium
- Confidence
- 83% confidence
- Finding
- The skill includes file-writing helpers that are outside the stated search-and-lookup scope, enabling local persistence of returned data. While not overtly malicious, this broadens the skill's capability and can write arbitrary API response content to disk, which may surprise the caller and create data handling or overwrite risks in an agent environment.
