Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is presented as a Remotion video-generation workflow, but it also instructs the agent to scrape third-party websites and retrieve remote assets. That expands the capability and trust boundary beyond the declared purpose, creating undisclosed network access and data-ingestion behavior that could surprise users or be misused to fetch untrusted content.
