Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented as a UI beautification/template application tool, but it also includes instructions to import arbitrary templates from GitHub and mutate persistent template registries. This expands the skill from local design assistance into remote content ingestion and system state modification, increasing supply-chain and persistence risk beyond what a user would reasonably infer from the manifest.
