Context-Inappropriate Capability
Medium
- Confidence
- 91% confidence
- Finding
- The skill explicitly tells the executing agent to read the user's agent code, character config, or system prompt to recommend monetization settings. That access can expose secrets, proprietary prompts, credentials, or other sensitive context that is not strictly necessary for a basic SDK integration, and the skill does not require minimizing scope or obtaining explicit consent first.
