Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill’s advertised purpose is text-to-video generation, but it also instructs the agent to upload arbitrary local files and import content from URLs. That expands data-access and network-fetch capabilities beyond what a user would reasonably expect, increasing the risk of unintended exfiltration of sensitive local files or ingestion of untrusted remote content.
