Context-Inappropriate Capability
Medium
- Confidence
- 87% confidence
- Finding
- The parser forwards arbitrary user requests to a third-party API for interpretation, which can disclose sensitive user content and expands the skill's effective capabilities beyond local parsing. Because the skill context provides no clear consent, data-classification boundary, or necessity justification, this is an unjustified external-processing path that can leak proprietary or personal data.
