Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The changelog describes a network-based self-update mechanism executed from within a skill whose declared role is only a task-processing framework. Even though later entries discuss making it safer, a skill that reaches out to the network to discover or fetch updates materially expands its authority and creates a supply-chain risk path from remote content into future execution.
