Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill explicitly encourages using browser, web search, CLI, and spawned agents as part of its default operating model, which expands behavior beyond a memory/proactivity skill into networked and orchestration actions. Even though some guardrails are present, this materially increases attack surface and can lead to unsafe external interactions or execution of unreviewed workflows.
