Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest materially understates the skill's behavior by advertising only three operations, while the body also performs a fourth hardening function and includes a sizable A/B evaluation and orchestration workflow. This mismatch can mislead operators and routing logic about what the skill is capable of, reducing informed consent and increasing the chance the skill is invoked in contexts where broader file access or agent spawning is unexpected.
