Description-Behavior Mismatch
High
- Confidence
- 94% confidence
- Finding
- The skill is presented as a narrowly scoped HTML/CSS/JS frontend design generator, but later advertises generic file processing, API integration, and command execution capabilities. This scope expansion is dangerous because it can cause an agent or user to treat the skill as authorized to access files, invoke external services, or run shell commands unrelated to the stated design task, increasing the attack surface for prompt injection and unintended privileged actions.
