Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The README describes behavior that goes beyond a transient identity declaration: it persists a Consent Key for future use and includes a tool to report when a badge was presented to a merchant. This creates a mismatch between the apparent scope of the skill and its documented capabilities, which can undermine informed user consent, expand data retention, and introduce tracking or authorization persistence risks if users expect a one-time credential exchange.
