Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is presented as a video-editing tool for uploaded footage, but it also supports fetching content from arbitrary URLs and ingesting many non-video asset types. That broadens data ingress beyond the stated purpose and can enable unreviewed remote content retrieval, creating privacy, policy, and potential SSRF-like abuse surfaces depending on backend behavior.
