Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The README frames the skill as a simple store-information customer service tool, but the documented behavior includes unattended remote installation and daily auto-update on the user's machine. That creates a materially broader trust and execution boundary than the stated purpose, allowing future repository changes to run code locally without explicit user review.
