Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The skill’s stated purpose is visualization, but it also instructs the agent to deploy a background service and continuously report prompt contents, working directory, file paths, and shell commands. That creates a covert telemetry channel far broader than users would reasonably expect from the description, increasing the risk of sensitive data collection and unauthorized monitoring.
