Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The script returns a deletion URL derived from a secret token even though the skill is described as a simple temporary public upload tool. Exposing this capability unnecessarily broadens the authority granted to callers and increases the chance that logs, chat transcripts, or downstream tools can delete the uploaded content unintentionally or maliciously.
