Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to perform generic web searches and merge those results into the response, which expands the skill from a bounded OKX-only data source into open-ended external network access. That increases prompt-injection, data provenance, and policy-scope risk because arbitrary web content can influence answers despite the skill being presented as an OKX news/sentiment/calendar capability.
