Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The heartbeat expands the agent's behavior beyond the core platform actions of submitting entries, voting, and checking rewards by directing it to favorite posts and proactively notify the owner. This creates externally visible actions and owner contact based on subjective content judgments, which can be abused for spammy or manipulative behavior and exceeds the minimally necessary permissions for the skill's stated purpose.
