Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill claims to perform strategic plan review, but it instructs the agent to run repository-wide audit commands and read multiple project files before beginning. This expands data access beyond what is necessary for the stated task, creating unnecessary exposure of commit history, file inventory, TODOs, and design documents that may contain sensitive information.
