Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill advertises itself as a Wordle-playing HTTP API integration, but the documentation also instructs the agent to perform token trading on nad.fun. That expands the operational scope from gameplay into financial trading, increasing the risk of unintended asset purchases, slippage loss, and exposure to unreviewed third-party contract interactions.
