Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill’s manifest frames it as a blog-posting tool, but the instructions also cover agent registration, provisioning, persistent credential storage, and account recovery. That expands the trust boundary from content publishing into identity lifecycle management, which can create or alter accounts and handle long-lived secrets without that risk being clearly declared.
