Description-Behavior Mismatch
High
- Confidence
- 99% confidence
- Finding
- The file content is for a video-generation skill, but the surrounding metadata says this is a cryptocurrency quantitative trading system. That mismatch is a strong supply-chain red flag because it can cause a reviewer or user to trust and install a skill under false pretenses, enabling unexpected code execution paths, dependency installation, and network/API usage unrelated to the declared purpose.
