Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The script’s security promise is weakened by a first-class bypass flag that installs a skill without any scan. In a tool whose purpose is pre-install security enforcement, this creates an easy path for users, wrappers, or social engineering to defeat the protection and install unvetted content.
