Description-Behavior Mismatch
High
- Confidence
- 96% confidence
- Finding
- The skill is presented as an image remixing tool, but the instructions expose a substantially broader media-editing backend with session state, timeline manipulation, uploads, and export operations. This mismatch can cause users and host systems to grant permissions or send data under false expectations, enabling unintended backend actions and expanding the attack surface beyond the declared capability.
