Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly tells the agent to derive an organization ID from user profile or context and then use it to query organization-scoped guardrail data. That expands access from simple verification/discovery into potentially sensitive tenant-scoped administration data, and can cause cross-tenant or over-broad access attempts if identity and authorization are not made explicit to the user.
