Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to call an external API (`prompts.chat`) to fetch prompt content and incorporate it into worker personas. This expands the trust boundary from local orchestration/setup into network retrieval of untrusted third-party content, creating prompt-injection, privacy leakage, and supply-chain risk not necessary for the stated function.
