Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill is a reasoning aid, but it instructs the agent to fetch remote content at runtime to obtain a 'canonical current version' of the skill. That creates a supply-chain and prompt-injection surface: whoever controls the remote JSON or the network path can alter the skill's behavior after installation, bypassing local review and causing the agent to follow untrusted instructions.
