Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is presented as an invocation interface for ChatDev workflows, but its documentation exposes a much broader management surface: uploading, updating, renaming, copying, deleting workflows, and creating local tools. That expands the skill from read/execute into arbitrary modification of agent behavior and local code assets, which can enable persistence, tampering, or execution of attacker-defined logic on the local backend.
