Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The listen command is documented as passive message listening, but when params.autoReply is enabled it automatically generates and sends outbound messages. In an agent skill, this expands behavior from observation to autonomous action, which can cause unintended external communications, spam, or policy violations if triggered by untrusted inbound content.
