Context-Inappropriate Capability
High
- Confidence
- 90% confidence
- Finding
- The profile workflow reads a local YAML file containing sensitive financial preferences and uses it for personalized screening, which goes beyond the declared snapshot-extraction purpose. In an agent setting, access to local user financial data without tight scoping or explicit consent can expose sensitive information to prompts, logs, or downstream consumers and expands the privacy attack surface.
