Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The package metadata describes the project as a standalone procedural art generator, but the scripts and dependencies clearly add blockchain deployment, NFT minting, and Twitter/X promotion capabilities. This mismatch can mislead reviewers and users about the skill's real privilege and network surface, increasing the risk of unintended wallet, contract deployment, or social-posting actions in an autonomous agent context.
