Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest advertises a narrow set of supported formats and local files, but the body documents many more file types plus remote URL ingestion. That mismatch can mislead users and downstream tooling about what data the skill may accept and transmit, increasing the chance of unexpected handling of sensitive or untrusted content.
