Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The README describes behavior beyond the skill's stated purpose: it not only forks repositories but also automatically stars them. This creates an undocumented account action on the user's behalf, which violates least surprise and can be abused for unauthorized engagement or reputation manipulation.
