Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill goes beyond passive documentation and instructs the agent how to invoke an MCP execution/backtesting function with concrete parameters. That creates a capability-escalation risk: a user asking for help with expressions could indirectly trigger operational actions or simulated trading workflows the skill was not supposed to autonomously perform.
