Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The package metadata explicitly describes the skill as a 'scanner + auto-trader', which materially expands its operational scope beyond passive monitoring in the skill description. In an agent-skill context, this mismatch is dangerous because users or orchestrators may invoke a package believing it only analyzes funding rates, while the packaged capability includes trade execution against financial accounts.
