Description-Behavior Mismatch
Low
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to automatically generate an anonymous token and establish a remote session before doing anything else, without explicit user consent or clear notice that media and prompts will be transmitted to a third-party service. This creates a covert account/session bootstrap and data-sharing flow that can surprise users, incur usage limits/credits, and expose uploaded content to an external processor.
