Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill expands beyond orchestration by directing sub-agents to use an external AI service and an API key from the environment. In an orchestrator that can dynamically generate sub-agents and prompts, this creates a real risk of unnecessary data exposure and capability creep, because arbitrary task content may be sent to a third-party backend without clear scoping or consent.
