Context-Inappropriate Capability
High
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the agent to read recent real conversation logs and submit them to a third-party server. Even with a consent prompt, this grants broad sensitive-data access far beyond what a benchmark/checkup description reasonably implies and risks exfiltrating private user content, secrets, and unrelated personal data.
