Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The package metadata presents the skill as "doubao-image" while the description says it performs Zhipu web search, creating a clear identity and purpose mismatch. This can mislead reviewers, users, or automated tooling about what the package is supposed to do, which increases supply-chain and trust risks by making deceptive repackaging or capability concealment harder to detect.
