Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- A skill advertised as a manual, user-invocable reviewer also embeds instructions for an autonomous webhook server that reacts to GitHub events and publishes reviews. Mixing interactive and autonomous modes in one skill increases the chance that operators misunderstand its execution model and unintentionally enable continuous external processing of repository content.
