Description-Behavior Mismatch
Medium
- Confidence
- 76% confidence
- Finding
- The code invokes a server-side modification endpoint (`POST /api/trim`) using user-controlled `task_id`, `track_name`, `start_time`, and `end_time`, despite the skill being described only as a separator. This hidden capability increases attack surface and may enable unauthorized or unreviewed server-side file processing if backend authorization, input validation, or ownership checks are weak.
