Description-Behavior Mismatch
High
- Confidence
- 96% confidence
- Finding
- The manifest presents the skill as a safe, read-only workspace browser, but the declared tools and later documentation expand scope to write access, API integration, and command execution. This mismatch can mislead users or orchestration systems into granting or invoking capabilities that exceed the advertised trust boundary, enabling unsafe file modification or arbitrary command use under a benign label.
