Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The manifest frames the skill as a simple Codex implementation helper, but the body expands into an autonomous workflow that performs branch creation, dependency installation, git push, PR creation, review orchestration, notifications, retries, and cleanup. This scope mismatch is dangerous because it can cause the skill to be invoked for ordinary coding requests while actually enabling broad unattended repository and system actions.
