Context-Inappropriate Capability
Medium
- Confidence
- 99% confidence
- Finding
- The upload request explicitly sets verify=False, disabling TLS certificate validation. This allows a man-in-the-middle attacker to intercept or alter uploaded video content, authentication headers, and API responses, which is especially risky because the skill transmits local file contents and IVVR credentials-derived signatures to an external service.
