Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The code fetches attacker-controlled URLs and writes the response to a local temporary file without restricting scheme, host, content type, or size. In a skill that processes images, this creates SSRF and unsafe file-ingestion risk because an attacker could supply internal network URLs or non-image payloads that get stored and potentially processed downstream.
