Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is presented as a workspace sync utility, but the documented backup feature materially expands scope to snapshot config, cron, and memory data to cloud storage. That creates a significant confidentiality risk because operators may enable it expecting only workspace file sync, while actually exporting broader sensitive agent state.
