Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill markets itself as a simple video upload/edit tool, but the documented upload flow also accepts arbitrary URLs and a much broader set of asset types than the manifest suggests. This expands the data-ingestion surface without clear user disclosure or constraints, increasing the risk of unexpected remote fetching, privacy issues, and misuse of the agent to retrieve third-party content.
