Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill is presented as a writing aid, but its workflow instructs the agent to read a persistent local profile file containing personal information. That is a capability expansion beyond what the manifest signals, and it can lead to collection and reuse of sensitive user data without clear prior consent or scope limitation.
