Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as a distributed inference routing/scheduling layer, but it also documents remote model lifecycle mutation endpoints that can pull or delete models on other nodes. In an agent setting, this expands the effective privilege of the skill from observation/routing to state-changing fleet administration, which can trigger large downloads, evict models, disrupt service, and modify remote hosts if invoked without strong user consent and authorization.
