Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill’s declared purpose is image generation, but it also instructs the agent to locate and modify JSON files under ~/blog-meta. This expands scope from creating a new output file to editing existing user data without clearly declaring that behavior, increasing the risk of unintended file tampering or incorrect metadata updates.
