Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented as a narrowly scoped hug-photo animation tool, but the embedded documentation exposes a broader remote media-editing and export pipeline with generalized session, upload, state, and render capabilities. This scope expansion can cause the agent to perform actions the user did not reasonably expect, increasing the risk of unintended remote processing, broader data handling, and abuse of the linked backend beyond the declared purpose.
