Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is presented as an orchestration/task-decomposition helper, but it also embeds automatic outbound messaging behavior, including real-time WeChat/user-channel pushes. That expands its effective privileges from internal coordination to external communication, creating a risk of unreviewed data disclosure, spam, or exfiltration of task contents to third-party channels.
