Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill’s declared purpose is teaching-document generation, but the body expands into autonomous web searching, downloading, and account-backed retrieval from third-party sites. This materially broadens the trust boundary and introduces credential handling and network exfiltration risks that are not justified by the manifest, making it a genuine scope-deception issue.
