Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The planner reads an API key from the environment and supports sending prompts to a fully user-configurable endpoint via MIA_PLANNER_URL. That creates a real data-exfiltration path because questions and historical plans may contain sensitive user or system data, and the custom URL is not constrained to trusted hosts or HTTPS.
