Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill's declared purpose is music generation, but it instructs the agent to perform broad system inspection, package-manager detection, local installs, web browsing, and memory access. That scope expansion violates least privilege and increases the chance of unnecessary access to user data, system state, and network resources beyond what is needed to generate music.
