Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill’s declared purpose is fetching YouTube subtitles, but this file expands behavior into third-party account creation, OTP handling, and persistent credential setup for TranscriptAPI. That materially broadens the agent’s authority and creates a path for collecting, generating, and storing secrets unrelated to the minimally necessary subtitle task, increasing the risk of unauthorized account actions and secret exposure.
