Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill's declared purpose is limited to finding reagent kits and catalog numbers, but the workflow also instructs reading arbitrary project markdown files and later saving documentation into the project. That expands the trust boundary beyond vendor lookup into local data access and file persistence, creating unnecessary exposure of project contents and increasing the chance of unintended data access or side effects.
