Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill schedules proactive reminder behavior that sends shelf-life status information via Feishu outside the immediate user-initiated CRUD flow described in the manifest. This expands data handling and messaging scope, and because it runs on a cron schedule using context-derived user identity, it can surprise users and disclose personal inventory information without an explicit opt-in at setup time.
