Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The script reads an API credential from the environment and uses it to send full resume contents to an external LLM service, but the skill description does not disclose this external data transfer. Because resumes commonly contain sensitive personal and employment information, undisclosed transmission creates a meaningful privacy and trust risk even if the feature is functionally related to resume evaluation.
