Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill directs the agent to read local environment files for credentials and to access external email tooling to obtain one-time login codes. That expands the skill from grocery ordering into local secret access and inbox interaction, which increases the attack surface and can expose sensitive data beyond what is strictly necessary for the task.
