Context-Inappropriate Capability
High
- Confidence
- 99% confidence
- Finding
- The request explicitly sets rejectUnauthorized: false, which disables TLS certificate validation and allows man-in-the-middle interception or spoofing of the outbound API connection. In a logistics data-query skill that sends an authentication token in headers, this can expose credentials and permit tampering with returned operational data.
