Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill’s stated purpose is fetching YouTube captions, but this document instructs the agent to create third-party accounts, perform OTP-based authentication, and persist API credentials for future sessions. That materially expands the skill’s authority from read-only content retrieval into account creation and long-term secret management, which increases the blast radius if the skill is abused or misconfigured.
