Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The README explicitly instructs users to run an activation script that injects protocol text into persistent agent identity files such as SOUL.md, and later references removing the same protocol from SOUL.md or AGENTS.md. This creates cross-session behavioral persistence outside normal per-task consent boundaries, which is risky because a seemingly simple visibility feature is implemented by modifying core instruction sources that can silently influence future agent behavior.
