Context-Inappropriate Capability
Low
- Confidence
- 79% confidence
- Finding
- The chart auto-send rule introduces outbound data transmission to an external notification channel that is not part of the declared core capability set. In a trading skill that can access balances, positions, analytics, and potentially sensitive charts, automatic sending increases the risk of unintended disclosure to third-party endpoints or misconfigured channels.
