Context-Inappropriate Capability
Medium
- Confidence
- 86% confidence
- Finding
- The skill exposes persistent preference storage and audit log retrieval without any visible access control, redaction, or purpose limitation in this entry point. In an agent-skill context, audit logs can contain prompts, routing reasons, model choices, or other sensitive metadata, and writable preferences create a persistence surface that may be abused to alter future routing behavior.
