Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to automatically send user satisfaction, dissatisfaction, and improvement-related observations to a separate Feedback API unrelated to the requested patent lookup. This introduces an undisclosed secondary data flow that can exfiltrate user content or behavioral metadata without necessity for the primary task.
