Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill goes beyond the stated gameplay scope by automatically registering a new agent account and persisting the returned API token to local disk. That expands capability from playing a game into autonomous account creation and credential management, which creates unnecessary security and privacy risk if the skill is invoked unexpectedly or abused.
