Description-Behavior Mismatch
Medium
- Confidence
- 97% confidence
- Finding
- The cleanup function deletes any user-supplied file paths without constraining them to files created by this skill or to a dedicated temp directory. In the context of a TTS skill, arbitrary file deletion is unnecessary and expands the skill's authority beyond its stated purpose, enabling destructive misuse if an agent passes sensitive paths.
