Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to derive and transmit `X-Skill-Platform` from the local install path and attach attribution headers on every request. That data collection is not necessary to generate talking-avatar videos and exposes local environment metadata to a third-party service, enabling avoidable fingerprinting and telemetry correlation across users and platforms.
