Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The publishing guide explicitly documents that large reference data is not packaged with the skill and is instead downloaded from GitHub at install time via a postinstall hook. For a prompt-recommendation skill, this creates a capability and trust boundary not reflected in the stated purpose: the effective behavior and content can change after publication based on remote data, reducing reviewability and enabling supply-chain style content changes without a republish.
