Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill is marketed as a photo-to-video tool, but the implementation advertises support for many additional media types including video, audio, and generic editing/export flows. This creates a scope mismatch that can mislead users and host systems about what data the skill can accept and transmit, increasing the risk of unintended exfiltration of non-photo content to the remote service.
