Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as a pipeline/planning utility, but it also instructs agents to send Discord notifications. That expands the capability surface from local project orchestration into external communications, which can leak task status, repository details, or sensitive outputs without the user's explicit awareness. In a cron-driven autonomous skill, undocumented outbound messaging is more dangerous because it can happen repeatedly without an active human in the loop.
