Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The skill is advertised as a simple free, no-auth image host, but the documentation also introduces a paid token-based upload flow via x402. This expands the skill’s operational scope into payments and token handling without clear need, increasing the chance an agent invokes billing-related actions or handles payment credentials in contexts where only free public hosting was expected.
