Description-Behavior Mismatch
High
- Confidence
- 95% confidence
- Finding
- The skill metadata presents the capability as producing architecture and planning artifacts, but the body of the design expands into a platform that uploads and executes untrusted SKILL.md content via an agent capable of CLI/Bash actions. This is dangerous because it disguises materially riskier behavior behind a benign planning-oriented description, increasing the chance that reviewers or users underestimate the exposure to remote code execution and data access.
