Description-Behavior Mismatch
Medium
- Confidence
- 92% confidence
- Finding
- The manifest presents the skill as a simple video-editing tool, but the body instructs the agent to perform authentication, session creation, and credit/account-related API operations automatically. This expands the skill's effective capability beyond the declared purpose, which can mislead users and host platforms about what the skill will do with credentials and remote services.
