Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The script exposes account credit balance and plan entitlement data, which is outside the narrowly declared purpose of generating videos from a user prompt. Even if intended for troubleshooting, this adds unnecessary account/billing inspection capability that can reveal sensitive subscription and usage metadata and expands what the skill can do beyond user expectations.
