Context-Inappropriate Capability
Medium
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to enumerate all wallet accounts and switch across them when the user says 'check all accounts' or 'all wallets,' which expands data access beyond the minimum needed for a portfolio-viewing action. In an agent setting, this increases the chance of over-collection and unintended disclosure of holdings from multiple accounts, especially if the user did not explicitly understand the scope of enumeration and switching.
