Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill metadata says it sends emails via SMTP, but the implementation also accepts an arbitrary local attachment path and reads that file into the outbound message. In an agent setting, this creates a clear exfiltration primitive: a prompt or downstream tool invocation could cause sensitive local files such as SSH keys, config files, tokens, or user documents to be attached and emailed off-host without the manifest making that capability explicit.
