Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The onboarding directs the agent to extract untrusted session metadata and configure recurring outbound notifications to external chat destinations via cron. That expands the skill from local markdown task management into persistent message delivery, creating a channel for unintended data disclosure, misdelivery, or abuse if metadata is wrong, spoofed, stale, or not explicitly user-approved. In this skill context, the behavior is more dangerous because scheduled reports may include task contents and continue sending automatically after setup.
