Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to 'update configuration model libraries and risk matrices' as part of post-task retrospection, which goes beyond generating a one-off wealth-management analysis or report. This expands the skill from bounded content generation into persistent process or knowledge modification, creating a pathway for unauthorized state changes, prompt drift, or contamination of reusable decision artifacts by untrusted user inputs.
