Description-Behavior Mismatch
High
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to create third-party TranscriptAPI accounts, handle OTP-based verification, and persist API secrets, which is materially outside the declared YouTube research/transcript retrieval scope. This expands the agent into credential handling and account lifecycle operations, increasing the risk of unauthorized external actions, secret exposure, and misuse of user identity.
