Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The script’s stated purpose is token rotation, but it also clears error and cooldown state for the same profiles. That hidden side effect changes rate-limit or failure-tracking behavior and can mask operational problems, making the skill do more than a user would reasonably expect from 'swap key'. In this context, modifying retry/failure metadata is not necessary to replace credentials and increases the risk of bypassing protective controls.
