Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The script gathers extensive metadata for skills with unknown provenance and persists it to disk in both a report and a pending-sources file. That goes beyond the stated minimum purpose of update checking and can expose locally installed skill inventory, author identifiers, homepage URLs, metadata fields, and directory structure to other local processes or users, creating an information disclosure risk.
