Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to retrieve a lawyer's phone number from case-assignment data and use the last six digits as a verification code. That expands data access beyond the user-provided SMS and creates unnecessary access to sensitive case contact information, increasing privacy exposure and the chance of unauthorized use of related data.
