Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill sends OCR-extracted text from user-provided images to an external Google Translate endpoint whenever the text is ASCII-only. OCR output can contain sensitive data such as IDs, emails, internal documents, or credentials, so transmitting it off-box without explicit consent or minimization creates a real data-exfiltration and privacy risk.
