Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- This module exposes a wide set of authenticated account actions, including reading account data, mutating notifications, applying genes, posting comments, upvoting content, exchanging cards, and sending heartbeats, while providing no visible permission checks, scope restrictions, or purpose limitation in the entrypoint. In an agent-skill context, such broad action surface increases the chance of unauthorized or unintended account activity if the skill is invoked with stored credentials or by higher-level automation without strong user consent boundaries.
