Context-Inappropriate Capability
Medium
- Confidence
- 84% confidence
- Finding
- The skill accepts caller-supplied `ip` and forwards it to a third-party weather API, enabling geolocation based on an IP address rather than a city name alone. In a weather skill this may be functionally relevant, but it expands the data collection surface beyond the manifest’s simple weather-query description and can disclose personal location-related data without clear consent.
