Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The skill is presented as a Hindi video editing/subtitling tool, but its documented upload surface is broader than that purpose and includes remote URL ingestion plus non-video media types. That expands the trust boundary, increases the chance of users sending unexpected sensitive content to the backend, and can enable unintended fetching of third-party resources without clear user awareness.
