Description-Behavior Mismatch
Medium
- Confidence
- 95% confidence
- Finding
- The skill broadens its purpose from recovering the current or previous session to allowing any user to retrieve arbitrary session transcripts. This creates an access-control and privacy problem because it enables cross-session disclosure of potentially unrelated or sensitive conversations beyond the minimum needed recovery scope.
