Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill calls client.auto_redeem() on startup, which performs portfolio-affecting actions beyond the manifest's described behavior of scanning divergence and placing trades. Even if redemption is beneficial, undisclosed automated position management violates least surprise and can trigger unintended transactions or tax/accounting consequences for the user.
