Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill is described as a Paw installer/web-chat frontend, but this code also provides a full agent file editor for IDENTITY.md, SOUL.md, and USER.md via agents.files.get/set. That substantially expands the trust boundary: a user invoking a seemingly narrow UI skill can modify agent behavior and stored persona/configuration, which may alter future system behavior and expose sensitive operational capabilities.
