Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly documents `GET /api/chat/{matchId}/messages` as public, which would allow anyone with a match ID to read private conversations. In a dating context, chat content is highly sensitive and can reveal identities, preferences, and behavioral patterns, making unjustified public access a serious confidentiality issue.
