Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to collect a user's email address and send it to an external service to create an account, which expands from essay generation into identity collection and account provisioning. That is dangerous because it causes third-party data disclosure and account creation without clear necessity, consent flow, or privacy notice tied to the core writing task.
