Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The skill description says it is for direct transcript/summary generation from YouTube URLs and uploaded media/documents, but the API contract also grants broad read access to list and retrieve notes and folders. That expands the data-access surface beyond the stated purpose and can enable unintended browsing or exfiltration of previously stored user content if the agent is over-permissioned or prompted to enumerate data.
