Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill performs an out-of-band self-update check on every API call (except the update endpoint itself), which is unrelated to the declared note/knowledge-base functionality and is not disclosed to the user. This creates hidden network behavior and allows a remote service to influence execution flow by causing the tool to emit update metadata and abort with a special error code.
