Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill explicitly claims there is no persistent storage, network access, or credential-like data collection risk, yet the workflow later instructs API calls, external search, file reads, and audit-log creation. This mismatch is dangerous because operators or enforcement layers may trust the safety declaration and enable the skill in contexts where data exfiltration, unexpected system access, or retention should be prohibited.
