Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill is declared and described as a repository-management capability, but it also exposes unrelated AI chat, audio transcription, and video generation endpoints. This is dangerous because it expands the skill's effective privilege and data-exfiltration surface beyond user expectations, enabling transmission of arbitrary prompts, audio, or other content to external services under the same bearer token.
