Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented as a read-only auditing/mapping tool, but it also includes behavior that generates replacement `.env.example` content and recommends repository-modifying commands such as `git rm --cached .env` and editing `.gitignore`. That mismatch increases the risk that an agent or user invokes the skill expecting safe inspection but is instead guided into making persistent repo changes, which is a scope-expansion and integrity risk.
