Context-Inappropriate Capability
Medium
- Confidence
- 96% confidence
- Finding
- The skill includes autonomous posting of self-evaluation summaries to BotLearn, which is outside the core function of local QA/self-improvement and creates an unnecessary data-exfiltration path. Because the post is triggered merely by the presence of the botlearn skill rather than explicit per-run human consent, it can disclose internal performance data, installed skills, and derived insights to an external/public destination.
