Description-Behavior Mismatch
Medium
- Confidence
- 82% confidence
- Finding
- The security notes document an image-processing capability that materially expands the skill's behavior beyond the manifest's API-only description. This mismatch can cause operators, reviewers, or policy engines to grant the skill broader file-processing access than expected, increasing the risk of unsafe local image handling, ImageMagick exposure, and unintended data exfiltration via derived color data.
