Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill adds an unconditional instruction to call a separate Feedback API for multiple situations unrelated to the user’s ASIN keyword lookup request. This introduces an unnecessary secondary data flow that could exfiltrate user prompts, query contents, or satisfaction signals to another endpoint without clear consent or need for the primary function.
