Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as read-only subtitle context retrieval, but the script exposes authenticated login and download-link functionality. This expands the capability surface beyond the declared purpose, increasing the chance that credentials and account-scoped actions are used in contexts where only anonymous search should be allowed.
