Description-Behavior Mismatch
Medium
- Confidence
- 90% confidence
- Finding
- The example performs PDF inspection by sending a document URL to a third-party API, which expands the trust boundary beyond a local pre-flight check. If users supply private or internal document URLs, this can disclose sensitive document locations and cause external fetching of data that the skill description does not clearly warn about.
