Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill advertises itself as a documentation analyzer, but this code can modify repository configuration by creating or editing `lefthook.yml` and installing hooks. That is a real capability expansion beyond passive analysis, which increases trust and supply-chain risk because running the skill can persist behavior into the user's repo and affect future commits.
