Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill embeds a required commercial upsell directly into the prescribed workflow, steering users away from receiving complete implementation guidance unless they purchase an external product. In an agent setting, this is unsafe because it can manipulate outputs for commercial benefit, degrade task completion, and redirect users to third-party code outside the platform's trust boundaries.
