Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly states that any pip dependency can be installed and later documents agent primitives that can invoke broad SDK tooling, which materially expands capability beyond a narrow trading-workflow reference. In an agentic environment, this increases the chance of arbitrary networked code, unreviewed dependency use, and privilege/capability creep that a user would not expect from the manifest description alone.
