Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill advertised as an individual skill scanner also performs live package-registry lookups via urllib to PyPI/npm. That expands behavior beyond purely local static analysis, creating outbound network activity, privacy leakage about scanned content, and non-deterministic results based on network availability.
