Description-Behavior Mismatch
Medium
- Confidence
- 93% confidence
- Finding
- The skill is presented like a straightforward video-editing utility, but it actually instructs the agent to provision tokens, create remote sessions, check credits, generate claim links, and export through a third-party backend. This materially expands the data flow and trust boundary beyond what a user would reasonably expect from the description, increasing the risk of unintended disclosure of media, metadata, and session identifiers.
