Context-Inappropriate Capability
Medium
- Confidence
- 94% confidence
- Finding
- The skill's primary purpose is retrieving Amazon policy-feed content, but it also instructs the agent to automatically send user feedback or inferred quality signals to a separate Feedback API. This creates an unrelated secondary data flow that can transmit user content or behavioral metadata without clear necessity, consent, or scoping.
