Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill includes telemetry, analytics, and prior-learnings collection that are not necessary to perform a design review and are not clearly disclosed in the user-facing description. This expands data collection beyond least-privilege and can expose repository, branch, session, and workflow metadata to local logs or helper utilities without explicit user awareness.
