Scope Creep
High
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to create directories and write multiple files under ~/.workbuddy/tasks even though the manifest declares only file-read and network-access. This is a permission/behavior mismatch that can mislead operators, cause unauthorized persistence, and normalize stateful file writes outside the declared trust boundary.
