Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill performs outbound HTTP POST requests to a configurable webhook URL, but there is no manifest-scoped justification, allowlist, or validation of the destination. Even though the apparent purpose is memory integration, configurable network egress creates a data exfiltration path and broadens the trust boundary beyond the host application.
