Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The README describes functionality beyond simple financial-data retrieval: an automated crawler that logs into Tushare, solves captchas, scrapes large numbers of pages, writes repository files, and opens pull requests. In a skill advertised as a data-access tool, this materially expands the operational and security scope, introducing credential use, browser automation, filesystem modification, and remote content ingestion that could be abused or surprise users.
