Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill metadata describes posting signals and reading stats, but the body also documents modifying the user's remote profile, including payout wallet and active status. Undisclosed state-changing functionality increases the chance of unauthorized or unexpected account changes because reviewers may not realize the skill can alter account configuration.
