Context-Inappropriate Capability
Medium
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to derive or retrieve an organization ID from user profile/context and then use it for organization-scoped guardrail queries. That expands access from simple agent verification into potentially sensitive org-level data access, and risks confused-deputy behavior if the agent infers or reuses context without explicit user confirmation and authorization checks.
