Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The README explicitly instructs users to connect the output to ComfyUI, HyperFrames, Kling, and Runway for image/video generation and compositing, which exceeds the declared planning-only scope of the skill. This creates a scope-bypass risk: an agent or user may reasonably treat the skill as authorized to facilitate downstream generation workflows that the manifest says are out of bounds.
