Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The manifest presents the skill as an unauthenticated query tool, but the documentation also includes optional deployment as a persistent Discord/Telegram bot with scheduled notifications and tracking. This capability expansion changes the trust and risk profile materially because it introduces long-lived automation, external messaging, and credential handling that are not clearly reflected in the core skill description.
