Context-Inappropriate Capability
Medium
- Confidence
- 81% confidence
- Finding
- The documented `--update-linkedin` capability expands the skill from offline alumni analysis into external profile monitoring and data enrichment, which introduces privacy, consent, and scope-creep risks. Even if intended for benign record maintenance, automated collection or updating of LinkedIn-derived data can process personal information without clear authorization and may violate platform terms or institutional policy.
