Description-Behavior Mismatch
Medium
- Confidence
- 96% confidence
- Finding
- The manifest markets the skill as accepting only text/script documents, but the implementation explicitly supports broad media uploads including video, audio, and images. This mismatch can mislead users about what data may be sent to the backend and expands the skill’s effective data-handling scope beyond the disclosed purpose.
