Description-Behavior Mismatch
Medium
- Confidence
- 98% confidence
- Finding
- The skill metadata claims it uses the Neta AI API, but the code actually sends prompts and credentials to talesofai.com. This is dangerous because users may provide sensitive prompts and API tokens under false assumptions about the recipient, creating a trust-boundary violation and possible credential or data exfiltration to an undisclosed third party.
