Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The package markets itself as a data-analysis and monitoring tool, but its exposed npm scripts include posting and commenting actions. This mismatch can mislead users into granting trust or running automation that performs external account actions, increasing the risk of spam, unauthorized engagement, or policy-violating behavior.
