Description-Behavior Mismatch
Medium
- Confidence
- 86% confidence
- Finding
- The skill’s stated purpose is arXiv search/download/summarization, but it also initializes optional MongoDB-backed persistence for a reading list. This expands the skill’s data access and external connectivity beyond the declared scope, which can surprise users and create unnecessary data-handling risk in agent environments where least privilege and transparency matter.
