Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The spec explicitly allows loading an external vocabulary file from a remote location into an active conversation. In an agent skill context, this creates a supply-chain and prompt-injection surface because untrusted remote content can redefine terms, alter semantics, or introduce adversarial instructions that downstream agents may treat as authoritative.
