Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest describes transit lookup features but omits that the skill persistently stores sensitive home/work location data in a local JSON file and guides the agent to collect that data during setup. This is dangerous because users may disclose precise addresses without understanding they will be retained, creating privacy and retention risks beyond a simple schedule lookup tool.
