Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The photo-posting flow includes logic to edit the sharing audience and switch it to Public, which exceeds the documented behavior of merely posting text and photos. In a skill that automates posting to a personal account using live session cookies, changing privacy scope can unintentionally disclose personal content much more broadly than the user intended.
