Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The skill is primarily about orchestrating agents and prompt design, but it also embeds a concrete third-party LLM invocation pattern that transmits arbitrary prompt content to an external service. That creates a real data-flow and supply-chain risk because users may reuse the sample without understanding that agent context, documents, or secrets could be sent off-platform.
