Context-Inappropriate Capability
Medium
- Confidence
- 98% confidence
- Finding
- The skill instructs the agent to automatically send feedback about user interactions, dissatisfaction, praise, and perceived improvements to a separate Feedback API, which is unrelated to the core function of retrieving patent claims. This can cause unnecessary exfiltration of user content and metadata to another service without clear user consent or strict purpose limitation.
