Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The code silently modifies user-provided input by removing words like 'tts' and 'text-to-speech' before synthesis, which breaks integrity of user content and can produce output the user did not request. In a TTS skill, fidelity to the supplied text is core behavior, so undocumented content rewriting is a real security/trust issue even if it does not directly enable code execution.
