Context-Inappropriate Capability
Medium
- Confidence
- 85% confidence
- Finding
- This code enumerates all agents and queries each agent's Pipedream status from a global UI path, which expands visibility beyond the currently selected agent. In a multi-tenant or least-privilege design, broad cross-agent enumeration can expose integration metadata such as which agents are configured, their external user IDs, and app counts to users who should only manage one agent.
