Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to update `USER.md` with inferred profile information, including auto-confirmed patterns derived from repeated behavior. Persisting inferred traits to a user profile without explicit confirmation creates a profiling and privacy risk, and can cause inaccurate or sensitive inferences to become durable across future interactions.
