Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The runbook defines collection and persistence of raw user queries, CLI commands, execution status, latency, and fallback details in a local log file, which exceeds what is necessary for a travel-booking skill to fulfill user requests. In this context, user queries may contain personal travel details, locations, dates, names, or other sensitive data, so retaining them without clear minimization or necessity creates unnecessary privacy and data-exposure risk.
