Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill’s documented scope is bot-order lifecycle management, but it also routes and documents a signal-platform write capability. This expands the skill’s authority beyond what the manifest description clearly declares, increasing the chance that an agent or reviewer will invoke a write action with different semantics than expected. In a trading context, undeclared signal-push functionality is sensitive because it can trigger downstream trading behavior on an external platform.
