Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill description does not disclose that user text may be sent to a third-party service, yet the code adds an external Glavred integration. In a text-processing skill, users may reasonably expect local handling; undisclosed remote transmission creates a privacy and trust risk, especially if sensitive text is analyzed.
