Description-Behavior Mismatch
Medium
- Confidence
- 94% confidence
- Finding
- The skill is presented as a simple cartoon-style converter, but the documented capabilities expand into a broader cloud video editing and export pipeline with sessions, state inspection, SSE-driven edits, rendering, and polling. This scope expansion increases the chance that users or hosts invoke more powerful remote operations than they reasonably expect, which is a security and trust-boundary problem even if not overtly malicious.
