Description-Behavior Mismatch
Medium
- Confidence
- 83% confidence
- Finding
- The skill’s stated purpose is temporary media hosting, but it also includes a helper that retrieves arbitrary remote URLs and republishes them locally. That expands the trust boundary and can enable SSRF-like access to internal resources, unauthorized mirroring of third-party content, and ingestion of attacker-controlled files into the hosting environment.
