Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill presents itself as a simple image-to-video generator, but the documented API surface exposes generic session editing, state inspection, and export capabilities that go beyond the advertised purpose. This mismatch increases the chance of overbroad backend access being used to manipulate or exfiltrate unrelated media/session content, especially if the agent is granted user files and follows broad natural-language instructions.
