Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill directs the agent to create and persist a client identifier under the user's home directory to obtain anonymous tokens. This introduces unnecessary local state and cross-session tracking for a video-generation skill, and can occur without meaningful user awareness or consent. Persisted identifiers can enable correlation of activity over time and expand privacy risk beyond the immediate request.
