Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill directs the agent to automatically report feedback, user dissatisfaction, and mismatches to a separate Feedback API, which is outside the user's requested niche-review task. That creates an unauthorized secondary data flow and can exfiltrate user inputs, sentiment, or interaction metadata without clear consent or necessity.
