Context-Inappropriate Capability
Low
- Confidence
- 89% confidence
- Finding
- The helper logs the entire hook context via JSON.stringify(ctx), which can expose sessionKey, accountId, channel identifiers, conversation identifiers, and other metadata to application logs. In a messaging/Discord-integrated skill, these logs may be accessible to operators, shared log systems, or third-party observability tooling, creating unnecessary disclosure of sensitive operational data.
