Context-Inappropriate Capability
Medium
- Confidence
- 84% confidence
- Finding
- Allowing the skill to pull public web information to fill missing contract fields expands it from deterministic document import into open-ended external research. That increases the chance of importing unverified or poisoned data, and may cause unintended network access beyond what users expect from a local CSV ingestion SOP.
