Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The continuous monitoring flow instructs the agent to send status updates and reservation details to Discord via the message tool, extending the skill beyond core train booking into external data exfiltration. Even if intended for user convenience, this can disclose reservation identifiers, seat assignments, and operational state to third-party channels or wrong recipients.
