Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill directs the agent to create new files under the skill directory when a style file is missing, which expands behavior from report generation into persistent modification of local resources. This is dangerous because user-triggered content generation should not mutate the installed skill or its reference corpus, and such writes could be abused to plant data, alter future runs, or violate sandbox and integrity expectations.
