Description-Behavior Mismatch
Medium
- Confidence
- 82% confidence
- Finding
- The skill is presented as a firewall for prompt injection, tool filtering, and input sanitization, but its trigger text expands scope to generic vulnerability scanning and encryption protection. This mismatch can cause the skill to be invoked for broader security tasks it likely cannot safely perform, leading to overtrust, misuse, or unsafe command execution under a misleading security label.
