Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The documented `gno publish export` capability expands the skill from local document search into content packaging for publication to an external service (`gno.sh`). That creates a real scope-expansion and data-exfiltration risk because an agent using this skill could prepare local notes for external sharing, including sensitive material, which is not implied by the skill's stated local-search purpose.
