Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The document instructs the skill to persist detailed travel-profile data across sessions using either platform memory or a local file, even though the skill is described as a one-shot weekend itinerary generator. This creates unnecessary collection and retention of personal preference/history data, expanding privacy risk and attack surface beyond what is needed for the stated functionality.
