Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The skill is presented as a narrow subtitle-generation tool, but its setup instructs the agent to install and auto-configure a much broader platform with hundreds of unrelated APIs. This violates least privilege and increases the chance that user data, credentials, or future agent actions are routed through an overbroad third-party integration far beyond the stated task.
