Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill’s manifest advertises narrow intent-based routing for weather, documents, and search, but the implementation recommends many additional capabilities and always includes exec. In a tool-selection component, over-recommending privileged tools expands the agent’s reachable attack surface and can cause unrelated user messages to gain shell or workspace capabilities they did not require.
