Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill is presented as a text-to-video tool for text/script uploads, but the instructions authorize a much broader media-editing pipeline including video, image, and audio uploads. This scope expansion increases the chance that users or host systems send more data than expected to a remote service, weakening informed consent and violating least-privilege expectations for the skill.
