Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs exposing a local Remotion development server through a public Cloudflare tunnel, which turns a local service into an internet-reachable endpoint. A dev server can expose source code, local assets, debug functionality, and potentially unintended filesystem or environment-derived data, making this broader and riskier than simple video generation.
