Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- This module transmits full tree data to a live service over a WebSocket, which expands the skill from local planning/export into networked data exfiltration or remote delivery. In the context of a planning skill, trees may contain sensitive project structure, tasks, notes, or identifiers, and the code allows sending that data to an arbitrary host without clear restriction or explicit user-consent enforcement in the module itself.
