Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The install script automatically installs a separate skill, `ranking-of-claws`, when its config is missing, even though this dependency is not disclosed in the provided skill description. Implicitly provisioning additional software expands the trust boundary and can surprise users or reviewers, especially because the extra skill may have its own privileges, network behavior, or side effects.
