Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill’s stated purpose is generating a single academic .docx, but it embeds mandatory network download, install, and upgrade behavior for external software. This expands the trust boundary far beyond document authoring and creates a supply-chain execution path where remote code is fetched and run on the host.
