Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill advertises broad capabilities such as file handling, API integration, and command execution, but the included implementation only performs local in-memory learning-plan generation. This mismatch is dangerous because agents or users may grant the skill elevated trust or permissions based on false claims, increasing the chance of unintended tool use, data exposure, or unsafe automation beyond the demonstrated behavior.
