Description-Behavior Mismatch
Medium
- Confidence
- 88% confidence
- Finding
- The skill is presented as an uploader that returns public URLs, but it also documents remote object deletion commands. This expands the effective capability from write-only upload to destructive storage administration, increasing the risk that the agent could be induced to delete data when the user only expected upload behavior.
