Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The manifest markets a narrowly scoped Bangla caption/voiceover generator, but the instructions expose a substantially broader remote video editing and rendering surface, including uploads, state inspection, SSE-driven edits, and export workflows. This scope mismatch can mislead users and host systems about what the skill is permitted to do, increasing the chance of unintended file handling, remote processing, or policy bypass through a seemingly specialized skill.
