Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The plugin explicitly tells the embedded agent, for untrusted voice input from anyone in the joined channel, that it has access to all normal tools and skills. That creates a privilege-boundary failure: spoken content can indirectly drive unrelated capabilities such as file, network, or other high-impact tools, greatly expanding the blast radius beyond simple voice interaction.
