Description-Behavior Mismatch
Medium
- Confidence
- 86% confidence
- Finding
- The catch-all rule routes 'Everything else' including generic editing requests like adding BGM to this skill, materially expanding it beyond lyric syncing. That can cause the agent to invoke a third-party cloud editing backend for broader media tasks than the user would reasonably infer from the skill name and description, increasing accidental data exposure and unintended actions.
