Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The installer writes an autonomous cron job that causes periodic agentTurn execution with instructions to message the user and potentially perform repairs based on later replies. That creates persistent post-install behavior and expands the skill from local auditing into unattended agent orchestration, which can trigger unintended actions, social-engineering opportunities, or abuse if the cron/jobs.json channel is trusted by the broader platform.
