Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill explicitly tells the agent to gather ERC-8004 registration inputs from stored memories, skills, and tools, which widens data access beyond what is necessary for the lending workflow. This can cause unrelated or sensitive metadata to be collected and repurposed for external transmission without strong scoping or user confirmation.
