Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill initializes optional MongoDB connectivity and configures persistent storage even though the declared capability is limited to searching, downloading, and summarizing arXiv papers. This creates an undeclared data-retention surface and expands the skill's effective privileges, which is dangerous because users and hosting platforms may not expect long-lived storage or database access from this tool.
