Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is framed as a stock-analysis assistant, but it instructs the agent to always write a PDF report to a local filesystem path. Unnecessary file-writing expands the capability surface beyond analysis into persistent local side effects, which can surprise users, leak sensitive content into shared storage, or be abused if report contents include confidential prompts or user data.
