Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill manifest says the capability is limited to local Markdown-to-PDF conversion, but the documentation broadens behavior to general pandoc format conversion, templates, metadata, DOCX/HTML output, and URL-based inputs. This creates scope drift that can mislead an agent into performing unintended file transformations or handling untrusted remote content beyond the declared trust boundary.
