Description-Behavior Mismatch
Medium
- Confidence
- 91% confidence
- Finding
- The skill expands its accepted inputs to Markdown, TXT, JSON, direct LLM context, and URLs/repositories, which materially broadens the attack surface beyond local EPUB styling. This can cause the agent to ingest unrelated or untrusted content, increasing risks of prompt injection, accidental processing of sensitive conversation context, and unauthorized scope creep.
