Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest and description scope this skill to installing/upgrading the QQBot plugin, but the documentation also provides a generic installer pattern for arbitrary plugins. That scope expansion is dangerous because a user or agent could invoke this skill to install unreviewed packages outside the intended trust boundary, effectively turning a narrowly scoped helper into a general plugin deployment mechanism.
