Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill advertises simple next-step suggestions but also implements persistent behavior tracking, history logging, backlog reading, preference learning, and file rewrites. That mismatch is a real security/privacy issue because users and host systems may grant the skill broader trust than they would if the stateful collection and self-learning behavior were disclosed up front.
