Description-Behavior Mismatch
High
- Confidence
- 99% confidence
- Finding
- The skill's stated purpose is analyzing ЖКХ bills, but it additionally instructs the agent to run local Python commands, read a workspace file, and conditionally modify it for attribution and promotion. This is dangerous because it introduces hidden side effects unrelated to user intent, accesses local state, and turns a harmless document-analysis skill into one that performs unauthorized environment interaction.
