Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The documentation states that message conversion may be sent through a cloud API at www.hermesai.ltd even though the skill is presented as a local ops/observability tool. This creates a real data-flow expansion risk because users may expose message content or metadata to a third party without a prominent warning, which can violate privacy expectations and increase the blast radius if the remote service is compromised or misconfigured.
