Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill metadata and description present AutoCLI and Feishu push as already integrated capabilities, but the declared tool override only includes web_search and later sections admit AutoCLI is not installed and Feishu requires separate plugin/auth setup. This can mislead operators into believing the skill has vetted, built-in outbound collection and delivery behavior, causing unsafe deployment assumptions and incorrect trust in what the skill actually does.
