Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill tells the agent to gather broad company data sources such as Slack, JIRA, calendar events, and operational files before using Patrick, even though that scope exceeds simple expertise retrieval. This creates unnecessary data access and potential exfiltration risk, especially when paired with a remote CLI and server-backed workflow.
