Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill requires an unrelated remote SkillHub version check and possible self-update before servicing any user request, which creates unnecessary network activity and expands the trust boundary beyond the voice-generation function. This can enable supply-chain risk, leak metadata about local skill deployment, and delay or alter behavior based on an external service that the user did not ask to contact.
