Description-Behavior Mismatch
Medium
- Confidence
- 84% confidence
- Finding
- The skill is presented as a chat-only local tracker, but it conditionally invokes an external tool for card generation. Introducing an external executable into a health-logging workflow increases attack surface, creates potential data-sharing beyond local storage expectations, and may expose sensitive medical/bodily-function information to another component without clear consent boundaries.
