Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill is presented as app-development delegation, but its actual behavior is to transmit the user's request to a backend HTTP endpoint via exec and curl. That mismatch matters because users may believe the agent will handle the task locally, while the skill silently forwards potentially sensitive prompts to another service.
