Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The combined-mode prompt expands a download skill into a broader workflow that requests credential setup and seeks consent for uploading audio and sending content to third-party ASR/translation services. That scope creep is security-relevant because a user invoking a download-only skill may not expect data exfiltration or credential configuration, increasing the chance of unintended disclosure or misuse. In this context, the prompt does at least disclose the external processing, which reduces severity, but the mismatch with the declared skill purpose still makes it a real vulnerability.
