Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill metadata frames the capability as limited persona install/switch/list/restore, but the body also includes publishing souls, token-based login, memory sync to GitHub, swarm, and platform detection. This scope mismatch can cause an agent or user to invoke the skill under false assumptions, enabling data-transfer or account-affecting actions that exceed the declared purpose.
