Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The manifest restricts Bash access to read-oriented OpenAnt commands, but the skill body instructs the agent to perform state-changing operations such as create, claim, start, submit, and review. This mismatch is dangerous because it can cause the model to plan or attempt actions outside the declared permission boundary, undermining tool-governance assumptions and increasing the risk of unauthorized workflow changes if enforcement is weak or bypassable.
