Description-Behavior Mismatch
High
- Confidence
- 97% confidence
- Finding
- The documented behavior goes far beyond a simple 'handshake' or service discovery skill: it explicitly describes deploying `agent_shell.py`, exposing `/run`, and using it as a substitute for SSH to execute arbitrary remote tasks. This is dangerous because the skill framing can mislead users into enabling a remote administration backdoor they may not recognize as full remote code execution.
