Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The documented workflow instructs a spawned sub-agent to send generated files to a hard-coded Telegram target and then delete the local file. That expands the skill from local image generation into autonomous exfiltration and destructive file handling, creating a real risk of data leakage and unintended actions outside the user's immediate control.
