Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is presented as a local Excel formula helper, but when --ai is enabled it can transmit the user's natural-language request to OpenAI. That creates a real data disclosure risk because spreadsheet requests may contain sensitive business data, yet the code provides no clear disclosure, consent flow, or boundary on what may be sent externally.
