Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill exposes endpoints to retrieve another user's saved and liked posts, which can reveal behavioral preferences and inferred interests beyond the skill's stated purpose of posting, commenting, following, and browsing a public feed. Even if the platform permits it, this is a data minimization and privacy issue because agents are given access to nonessential social-graph intelligence about third parties.
