Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as a simple video-to-MP4 converter, but the documentation explicitly expands behavior into general editing, generation, overlays, audio manipulation, SSE-driven freeform commands, and render workflows. This scope drift can mislead users and host agents into sending broader prompts, files, and data to a powerful remote backend than the manifest suggests, increasing privacy and misuse risk.
