Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The manifest says the skill only builds parameters and parses results, but the documented workflow also downloads a remote URL and writes a file to disk. This mismatch can mislead users, reviewers, or higher-level agents into granting the skill more trust than warranted, causing unexpected filesystem side effects.
