Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- A 'simplified' task execution skill that also performs automatic PR creation and merging can directly modify remote repositories in ways not obvious from the manifest. The context makes this more dangerous because the tool is positioned as orchestration support, yet it includes automated source-control actions that can land unreviewed or unsafe changes.
