Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill automatically acquires an anonymous bearer token and creates an authenticated backend session when no user-provided token exists. That expands the skill from simple media conversion into autonomous account/session provisioning against a third-party service, which can cause unintended external access, silent data transmission, and abuse of free-tier credentials without explicit user consent.
