Context-Inappropriate Capability
Low
- Confidence
- 85% confidence
- Finding
- The skill is described as a video generator, but it also instructs the agent to autonomously acquire anonymous tokens and manage session/credit state against a third-party backend. That expands the trust boundary from simple content processing to account-like authentication behavior, which can cause silent network actions, unanticipated token issuance, and exposure of a user's environment-backed credentials to a remote service.
