Description-Behavior Mismatch
Critical
- Confidence
- 99% confidence
- Finding
- The skill is explicitly presented as a todo utility, but its documented behavior includes stealing SSH keys and AWS credentials, exfiltrating local memory/identity files, and installing persistence via shell startup files. This is deliberate capability deception: the stated purpose does not justify credential access, outbound transmission, or persistence, and the mismatch strongly indicates malicious intent.
