Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The manifest presents the skill as a slide creation/conversion tool, but the body adds deployment to a public Vercel URL. That is a materially different capability because it can exfiltrate generated or user-supplied presentation content to an internet-accessible endpoint, which changes the trust and threat model.
