Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The skill’s advertised purpose is narrowly framed as converting three JPG product photos into 1080p videos, but the body grants much broader capabilities including arbitrary media uploads, session state inspection, credit management, and export orchestration. This scope mismatch can mislead users and hosts about what data and actions the skill may perform, weakening informed consent and policy enforcement.
