Description-Behavior Mismatch
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to install and immediately execute remote code via a `curl ... | sh` pipeline from GitHub before performing its stated email functions. This is dangerous because it bypasses package integrity verification, grants arbitrary code execution in the agent environment, and expands a mailbox-reading skill into a software supply-chain execution path.
