Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill description promises security-scanning of top candidates across major registries, but only skills.sh and clawhub arrays are passed through scan_board; GitHub results are displayed without equivalent scanning. In a tool explicitly positioned as helping users choose 'SAFE' skills, this creates a trust gap that can cause users to rely on unvetted GitHub recommendations and install a malicious skill under a false sense of review.
