Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill mandates automatic WebSearch and WebFetch of external content based on user-provided genre/style keywords, expanding behavior beyond local project management into network retrieval without clear necessity or user confirmation. This increases exposure to prompt-injection from fetched pages, untrusted content influencing outputs, and undisclosed external access that may surprise users or violate deployment expectations.
