Context-Inappropriate Capability
Medium
- Confidence
- 89% confidence
- Finding
- The spec permits creating public SQL sharing links, which can expose query text and potentially embedded business logic or sensitive dataset references outside the expected project-editing workflow. In an agent context, this is risky because an agent could make internal queries externally accessible without a clear, high-friction user acknowledgment.
