Context-Inappropriate Capability
Medium
- Confidence
- 92% confidence
- Finding
- This module exposes a very broad set of Exchange read/write capabilities, including reading mail, sending mail, modifying calendars, deleting items, changing OOF settings, and accessing contacts and tasks, without any visible authorization, scope restriction, or purpose limitation. In an agent skill context, such overbroad capability materially increases the blast radius of prompt injection, misuse, or accidental invocation because a caller can pivot from simple read access to destructive or externally transmitting actions.
