Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The documented generic proxy allows arbitrary requests to the Detectify API, which materially expands the skill's effective permissions beyond the narrowly described purpose. That broad surface can enable unintended read/write/destructive operations if an agent follows user prompts too loosely or if the skill is invoked under an over-broad trust assumption.
