Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to automatically send user feedback, dissatisfaction, and improvement signals to a separate Feedback API, which is outside the core product-search function. This can exfiltrate user content or behavioral metadata to an additional endpoint without explicit user consent, purpose limitation, or clear data-minimization guarantees.
