Description-Behavior Mismatch
High
- Confidence
- 96% confidence
- Finding
- The skill is presented as a narrow video-to-MP3 converter, but its routing instructions send many user requests into broad NemoVideo editing, generation, upload, state, and export workflows. This capability mismatch can cause users and host agents to disclose files, prompts, and actions to a much more powerful remote service than the skill description implies, increasing the risk of unintended data exposure and misuse.
