Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill's stated purpose is local file search, but it also reads matched files and returns their full contents as base64. That materially expands the capability from discovery to exfiltration, which can expose sensitive local data without that behavior being clearly justified by the declared functionality.
