Description-Behavior Mismatch
Medium
- Confidence
- 83% confidence
- Finding
- The skill is labeled read-only, but it explicitly advertises retrieval of playback streams and signed playback URLs that can enable direct media access beyond simple metadata analysis. This creates a capability mismatch that may mislead an agent or operator into treating the skill as low-risk while it can facilitate downloading or redistribution workflows, with legal/compliance and policy-bypass implications.
