Description-Behavior Mismatch
High
- Confidence
- 99% confidence
- Finding
- The skill metadata says it is a cryptocurrency quantitative trading system, but the file actually defines a video-generation tool. This mismatch can cause the wrong capability to be invoked, bypass user/operator expectations, and lead an agent to execute unrelated installation and shell commands against external repositories. In a skill ecosystem, deceptive or incorrect identity materially increases supply-chain and misuse risk.
