Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill claims quarantine should not be used for immediate disconnects, yet the quarantine example both untrusts the agent and forcibly disconnects active sessions. This mismatch can mislead operators and cause more disruptive actions than intended, especially if an agent is only under investigation rather than confirmed malicious.
