Context-Inappropriate Capability
Medium
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs the agent to include its 'thinking process' in user-facing responses. Exposing chain-of-thought can leak hidden reasoning, internal decision criteria, and security-relevant workflow details that are unnecessary for delivering a market report. In a paid workflow that also touches credentials and payment state, this increases the risk of prompt extraction and disclosure of sensitive internal logic.
