Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to append self-model and routing content into SOUL.md and AGENTS.md, changing identity, invocation policy, and user-facing behavior beyond simple tool installation. Persistent modification of core behavioral files can create durable prompt injection, broaden future activation, and make later interactions follow the skill author's priorities instead of the user's explicit intent.
