Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The FAQ explicitly allows handling modules outside the declared supported Sensors Analytics scope by 'taking the job first' and adapting later. This weakens scope control and can cause the skill to process arbitrary external content or user requests that were not constrained, reviewed, or covered by the documented workflow, increasing the chance of misuse, bad fetch targets, and policy bypass.
