Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The dispatcher for a skill described as a scanner also installs and removes git hooks and writes repository configuration, expanding its behavior from passive analysis into modifying developer workflow. Even if intended as a convenience feature, this increases the trust boundary and can be abused to introduce persistent execution during commits or alter repository behavior in ways users may not expect from a scanning tool.
