Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill writes a PNG file directly to the user's Desktop, which is a side effect not disclosed by the skill description and is performed without consent at the write site. Unexpected filesystem writes can violate user expectations, overwrite existing files with predictable names, and create privacy or workspace clutter issues even if the content itself is non-executable.
