Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The document for a 'Context Loader' skill includes a write-capable endpoint that creates knowledge-network build tasks, which goes beyond passive retrieval and can trigger backend state changes. This is dangerous because an agent following this guidance may perform unintended or costly operations under the guise of context loading, especially if user prompts can steer it toward task creation.
