Context-Inappropriate Capability
Medium
- Confidence
- 95% confidence
- Finding
- The skill loads a local .context file and instructs the agent to source variables such as owner email, calendar ID, and credentials, which expands access beyond simple note retrieval into sensitive local configuration handling. This is dangerous because it enables implicit use of secrets and local state without clear user consent or strong scope controls, increasing the chance of unauthorized data access or cross-skill secret exposure.
