Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill manifest says analysis should use public futures market data only, but this file explicitly allows replacing defaults with real account values. That expands the data scope from public-market analysis into handling sensitive financial account information, which creates a mismatch in user expectations, privacy boundaries, and downstream decision logic. In a trading skill, that can lead to unnecessary collection or use of balances and positions despite the advertised analysis-only behavior.
