Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The gateway exposes functionality to persist downloaded preview images to local disk, which goes beyond a read-only HTTP proxy/search role described in the skill metadata. Although the path is constrained to remain under the skill root, this still creates a local write primitive that can consume disk space, leave residual data, and surprise users or higher-level agents that expect only transient responses.
