Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The document explicitly describes a built-in 'code attack engine' and frames code execution as a supported workflow, which expands the skill from verbal review into active exploit-style testing. Even though the broader skill description says code testing should require explicit user request, this file operationalizes attack execution and evidence collection in a way that could normalize or trigger risky code-running behavior against local workspace code.
