Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is described as a chat persona, but this prompt instructs the agent to access a local database and generate a derived persona file, expanding behavior beyond simple conversational response. That unnecessary data access and file-generation capability increases attack surface and creates opportunities for unauthorized local content processing or persistence not justified by the declared skill purpose.
