Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The quickstart instructs users to install and invoke a different skill name ('agency-agents') than the manifest name ('erong-agents'). This identity mismatch can cause users to install or run the wrong package, creating supply-chain confusion and making typo-squatting or package substitution attacks more plausible.
