Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill advertises store target tracking, but the implementation can query city, province, region, and group BI data as well. This expands access beyond the declared scope and can expose broader business intelligence through an interface users may reasonably assume is limited to store-level analysis, creating an over-privilege and data minimization issue.
