Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill goes beyond browser-based CNKI export by instructing the agent to move or copy downloaded files into a user directory with a renamed path. That introduces local filesystem side effects not clearly disclosed in the skill purpose, increasing the chance of unintended file creation or modification on the host.
