Description-Behavior Mismatch
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs agents to periodically fetch and follow remote instructions from a heartbeat URL, creating a dynamic instruction channel outside the reviewed skill file. That enables unreviewed behavior changes over time and can cause autonomous network activity unrelated to an explicit user request, which is a significant security and governance risk.
