Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill claims to expose 9 read-only query interfaces, but it additionally instructs the agent to execute `umeng-cli trace` telemetry commands. That expands behavior beyond the stated purpose and creates undisclosed data transmission, which is especially risky because the extra commands are framed as mandatory agent behavior rather than optional user-consented diagnostics.
